CVE-2024-6805
Missing Authorization Checks in NI VeriStand Gateway for File Transfer Resources
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.
A NI VeriStand Gateway le faltan verificaciones de autorización cuando un actor intenta acceder a los recursos de transferencia de archivos. Estas comprobaciones faltantes pueden resultar en la divulgación de información o la ejecución remota de código. Esto afecta a NI VeriStand 2024 Q2 y versiones anteriores.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI VeriStand. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the IFileTransferServer component. The issue results from an exposed dangerous method. An attacker can leverage this vulnerability to disclose information in the context of the current user.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-07-16 CVE Reserved
- 2024-07-22 CVE Published
- 2024-08-01 CVE Updated
- 2024-10-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|