First published: Mon Jul 22 2024(Updated: )
A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects VeriStand 2024 Q2 and prior versions.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
NI VeriStand | <2024 Q2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6675 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2024-6675, upgrade to NI VeriStand version after 2024 Q2 or apply any available patches.
CVE-2024-6675 is a deserialization of untrusted data vulnerability.
CVE-2024-6675 affects NI VeriStand versions up to and including 2024 Q2.
For successful exploitation of CVE-2024-6675, an attacker must trick a user into opening a specially crafted project file.