CVE-2024-6912: Hardcoded MSSQL Credentials
Published Jul 22, 2024
·Updated
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
Affected Software
2 affected components
All of the following
PerkinElmer ProcessPlus<=1.11.6507.0
Microsoft Windows
Remediation
Information
Install the patched version 2.0.0.
Event History
Jul 22, 2024
CVE Published
via MITRE·08:51 PM
Data Sourced
via MITRE·08:51 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6912?
CVE-2024-6912 is classified as a high severity vulnerability due to hard-coded MSSQL credentials allowing unauthorized access.
2
How do I fix CVE-2024-6912?
To fix CVE-2024-6912, update PerkinElmer ProcessPlus to version 1.11.6508.0 or later.
3
Who is affected by CVE-2024-6912?
CVE-2024-6912 affects all installations of PerkinElmer ProcessPlus up to version 1.11.6507.0 running on Microsoft Windows.
4
What kind of attack can CVE-2024-6912 enable?
CVE-2024-6912 allows attackers to log in and potentially manipulate or remove data from vulnerable installations.
5
Is CVE-2024-6912 a remote exploit?
Yes, CVE-2024-6912 can be exploited remotely due to the use of hard-coded MSSQL credentials.