Vulnerability Details CVE-2024-6805
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 67.0%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-6805
-
cpe:2.3:a:ni:veristand:2013
-
cpe:2.3:a:ni:veristand:2014
-
cpe:2.3:a:ni:veristand:2015
-
cpe:2.3:a:ni:veristand:2016
-
cpe:2.3:a:ni:veristand:2017
-
cpe:2.3:a:ni:veristand:2018
-
cpe:2.3:a:ni:veristand:2019
-
cpe:2.3:a:ni:veristand:2020
-
cpe:2.3:a:ni:veristand:2021
-
cpe:2.3:a:ni:veristand:2023
-
cpe:2.3:a:ni:veristand:2024