First published: Fri Nov 22 2024(Updated: )
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
<3.9.7 |
We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38646 is classified as a critical vulnerability due to its potential impact on resource confidentiality and integrity.
To fix CVE-2024-38646, ensure your Notes Station 3 software is updated to version 3.9.7 or later.
CVE-2024-38646 affects local authenticated users with administrator access on Notes Station 3.
CVE-2024-38646 is an incorrect permission assignment vulnerability that allows unauthorized access to critical resources.
No, CVE-2024-38646 requires local authenticated access for exploitation.