We have already fixed the vulnerability in the following version:
QuMagie 2.3.1 and later
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37503 | An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later |
Solution
We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-34 |
|
Mon, 16 Sep 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap qumagie |
|
| CPEs | cpe:2.3:a:qnap:qumagie:2.3.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap qumagie |
|
| Metrics |
cvssV3_1
|
Fri, 06 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later | |
| Title | QuMagie | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-06T16:58:21.953Z
Reserved: 2024-06-19T00:17:01.279Z
Link: CVE-2024-38642
Updated: 2024-09-06T16:58:17.981Z
Status : Analyzed
Published: 2024-09-06T17:15:16.677
Modified: 2024-09-16T12:33:13.277
Link: CVE-2024-38642
No data.
OpenCVE Enrichment
No data.
EUVD