# CVE-2024-38647

## Summary

- **CVE ID:** CVE-2024-38647
- **Severity:** HIGH
- **CVSS Score:** 7.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H)
- **CWE:** CWE-540, CWE-200
- **Published:** Nov 22, 2024
- **Last Modified:** Mar 13, 2026

## Description

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.

We have already fixed the vulnerability in the following version:
QNAP AI Core 3.4.1 and later

## Affected Products

- QNAP Systems Inc. — QNAP AI Core (3.4.x)

## References

- [CNA](https://www.qnap.com/en/security-advisory/qsa-24-40)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.65%
- **EPSS Percentile:** 49.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._