CVE-2024-6795

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.  An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database.
References
Link Resource
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:baxter:connex_health_portal:*:*:*:*:*:*:*:*

History

20 Sep 2024, 14:53

Type Values Removed Values Added
CPE cpe:2.3:a:baxter:connex_health_portal:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8
References () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01 - () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01 - Third Party Advisory, US Government Resource
First Time Baxter
Baxter connex Health Portal

10 Sep 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) En el portal de salud Connex publicado antes del 30/8/2024, se encontraron vulnerabilidades de inyección SQL que podrían haber permitido que un atacante no autenticado obtuviera acceso no autorizado a la base de datos del portal Connex. Un atacante podría haber enviado un payload manipulado al portal Connex que podría haber dado lugar a la modificación y divulgación del contenido de la base de datos y/o a la realización de operaciones administrativas, incluido el cierre de la base de datos.

09 Sep 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-09 20:15

Updated : 2024-09-20 14:53


NVD link : CVE-2024-6795

Mitre link : CVE-2024-6795

CVE.ORG link : CVE-2024-6795


JSON object : View

Products Affected

baxter

  • connex_health_portal
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')