CVE-2024-6456: SQL Injection vulnerability in AVEVA Historian Server
AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6456?
CVE-2024-6456 is considered a high-severity vulnerability due to the potential for SQL injection and escalation of privileges.
How do I fix CVE-2024-6456?
To address CVE-2024-6456, update to the latest version of AVEVA Historian Server as provided by the vendor.
What are the potential impacts of CVE-2024-6456?
Exploitation of CVE-2024-6456 could allow an attacker to execute malicious SQL commands and gain unauthorized access to sensitive data.
Who is affected by CVE-2024-6456?
CVE-2024-6456 affects users of AVEVA Historian Server, specifically those using the Historian REST Interface.
What kind of attack is associated with CVE-2024-6456?
CVE-2024-6456 is associated with social engineering attacks that trick users into opening specially crafted URLs.