Lucene search

K
nvd[email protected]NVD:CVE-2024-6121
HistoryJul 22, 2024 - 8:15 p.m.

CVE-2024-6121

2024-07-2220:15:04
web.nvd.nist.gov
8
redis
ni systemlink server
vulnerabilities

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.7%

An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.

Affected configurations

Nvd
Node
niflexloggerRange2023
OR
niflexloggerMatch2023q2
Node
nisystemlinkRange2024
OR
nisystemlinkMatch2024q1
VendorProductVersionCPE
niflexlogger*cpe:2.3:a:ni:flexlogger:*:*:*:*:*:*:*:*
niflexlogger2023cpe:2.3:a:ni:flexlogger:2023:q2:*:*:*:*:*:*
nisystemlink*cpe:2.3:a:ni:systemlink:*:*:*:*:*:*:*:*
nisystemlink2024cpe:2.3:a:ni:systemlink:2024:q1:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.7%