CVE-2024-6675: Deserialization of Untrusted Data Vulnerability in NI VeriStand Project File
Published Jul 22, 2024
·Updated
A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects VeriStand 2024 Q2 and prior versions.
Affected Software
1 affected component
NI VeriStand<2024 Q2
Event History
Jul 22, 2024
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Jun 9, 56622
Event
via FIRST·11:44 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-6675?
CVE-2024-6675 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-6675?
To fix CVE-2024-6675, upgrade to NI VeriStand version after 2024 Q2 or apply any available patches.
3
What type of vulnerability is CVE-2024-6675?
CVE-2024-6675 is a deserialization of untrusted data vulnerability.
4
What products are affected by CVE-2024-6675?
CVE-2024-6675 affects NI VeriStand versions up to and including 2024 Q2.
5
What is required for the exploitation of CVE-2024-6675?
For successful exploitation of CVE-2024-6675, an attacker must trick a user into opening a specially crafted project file.