CVE-2024-6456: Aveva Historian
High severity, CVSS 8.5. EPSS: 0.4% chance of exploitation in the next 30 days.
AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.
Affected products
- Aveva Historian: from 2020, before 2020_r2_sp1_p01 (fixed in 2020_r2_sp1_p01); from 2023, before 2023_p03 (fixed in 2023_p03); version 2023r2 only
- Aveva Historian Web Server: version 2023R2 only; from 2023, before 2023 P03 (fixed in 2023 P03)
Published 2024-08-15. Last modified 2026-06-17.