Description

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.  An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database.

INFO

Published Date :

2024-09-09T19:24:01.776Z

Last Modified :

2024-09-09T20:08:01.134Z

Source :

Baxter
AFFECTED PRODUCTS

The following products are affected by CVE-2024-6795 vulnerability.

Vendors Products
Baxter
  • Connex Health Portal
Hillrom
  • Connex Health Portal
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-6795.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact