CVE-2024-6806

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ni:veristand:2024:q2:*:*:*:*:*:*
cpe:2.3:a:ni:veristand:*:*:*:*:*:*:*:*

History

17 Sep 2024, 14:09

Type Values Removed Values Added
First Time Ni
Ni veristand
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/missing-authorization-checks-in-ni-veristand-gateway.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/missing-authorization-checks-in-ni-veristand-gateway.html - Vendor Advisory
CPE cpe:2.3:a:ni:veristand:2024:q2:*:*:*:*:*:*
cpe:2.3:a:ni:veristand:*:*:*:*:*:*:*:*
CWE CWE-862

22 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 21:15

Updated : 2024-09-17 14:09


NVD link : CVE-2024-6806

Mitre link : CVE-2024-6806


JSON object : View

Products Affected

ni

  • veristand
CWE
CWE-862

Missing Authorization