An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system.

We have already fixed the vulnerability in the following version:
Video Station 5.8.2 and later
Advisories

No advisories yet.

Fixes

Solution

We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later


Workaround

No workaround given by the vendor.

History

Fri, 13 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Qnap
Qnap video Station
CPEs cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*
Vendors & Products Qnap
Qnap video Station
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Qnap Systems
Qnap Systems video Station
Vendors & Products Qnap Systems
Qnap Systems video Station

Wed, 11 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
References

Wed, 11 Mar 2026 08:15:00 +0000

Type Values Removed Values Added
Description An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later
Title Video Station
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 0.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-03-11T14:12:35.283Z

Reserved: 2026-03-09T01:16:12.021Z

Link: CVE-2024-14024

cve-icon Vulnrichment

Updated: 2026-03-11T14:12:31.158Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-11T08:16:01.633

Modified: 2026-03-13T13:06:17.493

Link: CVE-2024-14024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-12T10:06:14Z

Weaknesses