CVE-2024-6912

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:perkinelmer:processplus:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:50

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Jul/13 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jul/13 - Exploit, Mailing List, Third Party Advisory
References () https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus/ - Exploit, Third Party Advisory () https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus/ - Exploit, Third Party Advisory

11 Sep 2024, 16:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Perkinelmer processplus
Microsoft windows
Microsoft
Perkinelmer
References () http://seclists.org/fulldisclosure/2024/Jul/13 - () http://seclists.org/fulldisclosure/2024/Jul/13 - Exploit, Mailing List, Third Party Advisory
References () https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus/ - () https://cyberdanube.com/en/en-multiple-vulnerabilities-in-perten-processplus/ - Exploit, Third Party Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:perkinelmer:processplus:*:*:*:*:*:*:*:*

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) El uso de credenciales MSSQL codificadas en PerkinElmer ProcessPlus en Windows permite a un atacante iniciar sesión y eliminar en todas las instalaciones propensas. Este problema afecta a ProcessPlus: hasta 1.11.6507.0.

23 Jul 2024, 03:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/13 -

22 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 21:15

Updated : 2024-11-21 09:50


NVD link : CVE-2024-6912

Mitre link : CVE-2024-6912

CVE.ORG link : CVE-2024-6912


JSON object : View

Products Affected

perkinelmer

  • processplus

microsoft

  • windows
CWE
CWE-798

Use of Hard-coded Credentials