CVE-2024-6456

AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.
CVSS

No CVSS.

Configurations

No configuration.

History

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) AVEVA Historian Server tiene una vulnerabilidad que, si se explota, podría permitir que un comando SQL malicioso se ejecute bajo los privilegios de un usuario interactivo de la interfaz REST de Historian que había sido diseñado socialmente por un malhechor para abrir una URL especialmente manipulada.

15 Aug 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 21:15

Updated : 2024-08-19 13:00


NVD link : CVE-2024-6456

Mitre link : CVE-2024-6456

CVE.ORG link : CVE-2024-6456


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')