CVE-2024-1156

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emerson:data_record_ad:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:flexlogger:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:g_web_development_software:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:labview_nxg:5.1:*:*:*:community:*:*:*
cpe:2.3:a:emerson:labview_nxg:5.1:*:*:*:real-time_module:*:*:*
cpe:2.3:a:emerson:labview_nxg:5.1:*:*:*:web_module:*:*:*
cpe:2.3:a:emerson:specification_compliance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:static_test_software_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:sts_software_bundle:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:systemlink_server:*:*:*:*:*:*:*:*

History

12 Feb 2025, 18:50

Type Values Removed Values Added
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html - Exploit, Vendor Advisory
CPE cpe:2.3:a:emerson:labview_nxg:5.1:*:*:*:community:*:*:*
cpe:2.3:a:emerson:systemlink_server:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:labview_nxg:5.1:*:*:*:web_module:*:*:*
cpe:2.3:a:emerson:g_web_development_software:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:static_test_software_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:sts_software_bundle:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:labview_nxg:5.1:*:*:*:real-time_module:*:*:*
cpe:2.3:a:emerson:data_record_ad:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:flexlogger:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:specification_compliance_manager:*:*:*:*:*:*:*:*
First Time Emerson specification Compliance Manager
Emerson sts Software Bundle
Emerson flexlogger
Emerson data Record Ad
Emerson g Web Development Software
Emerson systemlink Server
Emerson labview Nxg
Emerson
Emerson static Test Software Suite
CWE CWE-863

21 Nov 2024, 08:49

Type Values Removed Values Added
Summary
  • (es) Los permisos de directorio incorrectos para el servicio NI RabbitMQ compartido pueden permitir que un usuario autenticado local lea la información de configuración de RabbitMQ y potencialmente habilitar la escalada de privilegios.
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/incorrect-permissions-for-shared-systemlink-elixir-based-service.html -

20 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 15:15

Updated : 2025-02-12 18:50


NVD link : CVE-2024-1156

Mitre link : CVE-2024-1156

CVE.ORG link : CVE-2024-1156


JSON object : View

Products Affected

emerson

  • static_test_software_suite
  • labview_nxg
  • sts_software_bundle
  • specification_compliance_manager
  • data_record_ad
  • flexlogger
  • systemlink_server
  • g_web_development_software
CWE
CWE-276

Incorrect Default Permissions

CWE-863

Incorrect Authorization