PT-2024-8348 · Aveva · Aveva Reports For Operations
Published
2024-07-09
·
Updated
2024-08-14
·
CVE-2024-6618
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dream Report versions (affected versions not specified)
AVEVA Reports for Operations versions (affected versions not specified)
Description
The issue is related to errors in processing relative path to directory, which could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).
Recommendations
For Dream Report, consider restricting access to vulnerable directories to minimize the risk of exploitation.
For AVEVA Reports for Operations, avoid using relative paths in directory processing until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aveva Reports For Operations