An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content
and/or perform administrative operations including shutting down the database.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47824 | In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database. |
Solution
Baxter is unaware of any exploitation of this vulnerability and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required.
Workaround
No workaround given by the vendor.
Fri, 20 Sep 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baxter
Baxter connex Health Portal |
|
| CPEs | cpe:2.3:a:baxter:connex_health_portal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Baxter
Baxter connex Health Portal |
Mon, 09 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hillrom
Hillrom connex Health Portal |
|
| CPEs | cpe:2.3:a:hillrom:connex_health_portal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hillrom
Hillrom connex Health Portal |
|
| Metrics |
ssvc
|
Mon, 09 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database. | |
| Title | Vulnerability in Baxter Connex Health Portal | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Baxter
Published:
Updated: 2024-09-09T20:08:01.134Z
Reserved: 2024-07-16T17:54:02.625Z
Link: CVE-2024-6795
Updated: 2024-09-09T20:05:36.530Z
Status : Analyzed
Published: 2024-09-09T20:15:05.253
Modified: 2024-09-20T14:53:15.217
Link: CVE-2024-6795
No data.
OpenCVE Enrichment
No data.
EUVD