CVE-2024-14024

MEDIUM

QNAP Video Station 5.0.0-5.8.1 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0008
EPSS Percentile 0.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
qnap/video_station 5.0.0 - 5.8.2
Published Mar 11, 2026
Tracked Since Mar 11, 2026