CVE-2024-6456

EUVD-2024-47552
AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
avevahistorian
2020 ≤
𝑥
< 2020_r2_sp1_p01
ADP
avevahistorian
2023 ≤
𝑥
< 2023_p03
ADP