We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6675

Deserialization of Untrusted Data Vulnerability in NI VeriStand Project File



AssignerNI
Reserved2024-07-10
Published2024-07-22
Updated2024-08-01

Description

A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects VeriStand 2024 Q2 and prior versions.



HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-502 Deserialization of Untrusted Data

Product status

Default status
unaffected

Any version
affected

Credits

kimiya working with Trend Micro Zero Day Initiative 0x400109d8b0

References

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/deserialization-of-untrusted-data-vulnerability-in-ni-veristand-project-file.html

cve.org CVE-2024-6675

nvd.nist.gov CVE-2024-6675

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.