First published: Mon Sep 09 2024(Updated: )
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database.
Credit: productsecurity@baxter.com
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter Connex Health Portal | <2024-08-30 |
Baxter is unaware of any exploitation of this vulnerability and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6795 is considered a critical vulnerability due to its potential for unauthorized database access.
To fix CVE-2024-6795, upgrade the Connex health portal to the latest version released after August 30, 2024.
CVE-2024-6795 affects all versions of the Connex health portal released before August 30, 2024.
CVE-2024-6795 is a SQL injection vulnerability that allows attackers to interact with the database.
Yes, CVE-2024-6795 can be exploited by unauthenticated attackers remotely.