We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6806

Missing Authorization Checks In NI VeriStand Gateway For Project Resources



AssignerNI
Reserved2024-07-16
Published2024-07-22
Updated2024-08-01

Description

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.



CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version
affected

Credits

kimiya working with Trend Micro Zero Day Initiative 0x40013b83c0

References

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/missing-authorization-checks-in-ni-veristand-gateway.html

cve.org CVE-2024-6806

nvd.nist.gov CVE-2024-6806

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.