CVE-2024-6795: Vulnerability in Baxter Connex Health Portal
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.
An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content
and/or perform administrative operations including shutting down the database.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6795?
CVE-2024-6795 is considered a critical vulnerability due to its potential for unauthorized database access.
How do I fix CVE-2024-6795?
To fix CVE-2024-6795, upgrade the Connex health portal to the latest version released after August 30, 2024.
Who is affected by CVE-2024-6795?
CVE-2024-6795 affects all versions of the Connex health portal released before August 30, 2024.
What type of vulnerability is CVE-2024-6795?
CVE-2024-6795 is a SQL injection vulnerability that allows attackers to interact with the database.
Can CVE-2024-6795 be exploited remotely?
Yes, CVE-2024-6795 can be exploited by unauthenticated attackers remotely.