CVE-2024-38642 LOW

CVE-2024-38642: QuMagie

Vendor Qnap Systems Inc.
Product QuMagie
Weakness CWE-295
Published September 6, 2024
Last update September 6, 2024

CVSS base score

1.0/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L

What the vulnerability does

01Description

An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later

Key dates

02Disclosure timeline

September 6, 2024 CVE published
September 6, 2024 Record updated