CVE-2024-6619: Incorrect Permission Assignment for Critical Resource in Ocean Data Systems Dream Report
Published Aug 13, 2024
·Updated
In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.
Affected Software
1 affected component
Ocean Data Systems Dream Report
Remediation
Information
Ocean Data Systems recommends users update to the following:
* Dream Report 2023 R2: Version 23.3.18952.0523
For more information, see Dream Report Version 2023 R2 Released https://dreamreport.net/ .
AVEVA recommends users of affected versions upgrade to the versions listed below and apply the corresponding security update:
* Update to AVEVA Reports for Operations 2023 R2 https://softwaresupportsp.aveva.com/#/producthub/details or later
For more information, see security bulletin AVEVA-2024-006 https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2024-006.pdf .
Event History
Aug 13, 2024
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6619?
CVE-2024-6619 has a high severity rating due to its potential for privilege escalation and denial-of-service.
2
How do I fix CVE-2024-6619?
To fix CVE-2024-6619, update to the latest version of Ocean Data Systems Dream Report that addresses this vulnerability.
3
Who is affected by CVE-2024-6619?
CVE-2024-6619 affects users of Ocean Data Systems Dream Report who have not implemented the appropriate security updates.
4
What type of attack can be executed using CVE-2024-6619?
CVE-2024-6619 allows a local unprivileged attacker to escalate their privileges, potentially leading to a denial-of-service.
5
Can CVE-2024-6619 be exploited remotely?
CVE-2024-6619 cannot be exploited remotely as it requires local access to the affected system.