CVE-2024-6793: Deserialization of Untrusted Data in NI VeriStand DataLogging Server
Published Jul 22, 2024
·Updated
A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.
Affected Software
2 affected components
NI VeriStand<=2024
NI VeriStand=2024-q2
Event History
Jul 22, 2024
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Jun 9, 56622
Event
via FIRST·11:39 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-6793?
CVE-2024-6793 is rated as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2024-6793?
To mitigate CVE-2024-6793, update NI VeriStand to the latest version beyond 2024 Q2.
3
What kind of vulnerability is CVE-2024-6793?
CVE-2024-6793 is a deserialization of untrusted data vulnerability.
4
What versions of NI VeriStand are affected by CVE-2024-6793?
CVE-2024-6793 affects NI VeriStand 2024 Q2 and earlier versions.
5
What is required for an attacker to exploit CVE-2024-6793?
Successful exploitation of CVE-2024-6793 requires the attacker to send a specially crafted message to the DataLogging Server.