CVE-2024-6618: Aveva Reports For Operations

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).

Affected products

  • Aveva Reports For Operations: version 23.0.17795.1010 only
  • Aveva Reports For Operations 2023: version 23.0.17795.1010 only
  • Ocean Data Systems Dream Report 2023: up to and including 23.0.17795.1010

Published 2024-08-13. Last modified 2026-06-17.