Description
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Published: 2024-11-15
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-45924 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
History

Thu, 28 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:*

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00229}

epss

{'score': 0.0019}


Fri, 15 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 17:45:00 +0000

Type Values Removed Values Added
Description The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
Title Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Nextcloud Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-15T18:20:10.869Z

Reserved: 2024-11-11T18:49:23.558Z

Link: CVE-2024-52510

cve-icon Vulnrichment

Updated: 2024-11-15T18:20:04.569Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-15T18:15:29.497

Modified: 2025-08-28T14:21:08.737

Link: CVE-2024-52510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:09:37Z

Weaknesses