CVE-2024-6805

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ni:veristand:2024:q2:*:*:*:*:*:*
cpe:2.3:a:ni:veristand:*:*:*:*:*:*:*:*

History

17 Sep 2024, 14:13

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-862
First Time Ni
Ni veristand
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/missing-authorization-checks-in-ni-veristand-gateway.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/missing-authorization-checks-in-ni-veristand-gateway.html - Vendor Advisory
CPE cpe:2.3:a:ni:veristand:2024:q2:*:*:*:*:*:*
cpe:2.3:a:ni:veristand:*:*:*:*:*:*:*:*

22 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 21:15

Updated : 2024-09-17 14:13


NVD link : CVE-2024-6805

Mitre link : CVE-2024-6805


JSON object : View

Products Affected

ni

  • veristand
CWE
CWE-862

Missing Authorization