CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-6794

CVSS 9.8v3.1pub. 2024-07-22upd. 2024-11-21

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.

🤖 AI Analysis
How it works

An attacker sends a specially crafted network message containing a malicious payload to the Waveform Streaming Server. The server deserializes the received data without proper validation of its origin or content. As a result of this process, arbitrary code execution is possible in the context of the running server. The vulnerability is accessible remotely over the network without requiring any credentials.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code remotely (RCE) on the target system, which may lead to complete takeover of the machine, disclosure of sensitive data, and violation of system integrity and availability.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references: https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/deserialization-of-untrusted-data-vulnerabilities-in-ni-veristand.html

Who is affected

NI VeriStand 2024 Q2 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Ni Veristand

    APP
    Ni
    2024≤ 2024
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2024-6793CRITICAL9.8PL ✓same product

RCE przez niebezpieczną deserializację w NI VeriStand DataLogging Server

CVE-2024-6806CRITICAL9.8PL ✓same product

Brak weryfikacji autoryzacji w NI VeriStand Gateway — RCE

CVE-2024-6791HIGH7.8same product

A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in...

CVE-2024-6805HIGH7.5same product

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resour...

CVE-2023-5136MEDIUM5.5same product

An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure...