CVE-2024-6791: Directory Path Traversal Vulnerability in NI VeriStand with vsmodel Files
A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .vsmodel file. This vulnerability affects VeriStand 2024 Q2 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6791?
CVE-2024-6791 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-6791?
To mitigate CVE-2024-6791, ensure you update to the latest version of NI VeriStand released after the discovery of this vulnerability.
Who is affected by CVE-2024-6791?
CVE-2024-6791 affects users of NI VeriStand 2024 Q2 and earlier versions.
What causes CVE-2024-6791?
CVE-2024-6791 is caused by a directory path traversal vulnerability when loading specially crafted .vsmodel files.
What should I do if I have opened a vulnerable .vsmodel file related to CVE-2024-6791?
If you have opened a vulnerable .vsmodel file, it is recommended to run a thorough malware scan and apply security patches immediately.