PT-2024-8348 · Aveva · Aveva Reports For Operations

Published

2024-07-09

·

Updated

2024-08-14

·

CVE-2024-6618

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dream Report versions (affected versions not specified) AVEVA Reports for Operations versions (affected versions not specified)
Description The issue is related to errors in processing relative path to directory, which could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).
Recommendations For Dream Report, consider restricting access to vulnerable directories to minimize the risk of exploitation. For AVEVA Reports for Operations, avoid using relative paths in directory processing until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-09904
CVE-2024-6618

Affected Products

Aveva Reports For Operations