PT-2026-50888 · Ni · Grpc-Device
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NI grpc-device versions prior to 2.17.0
Description
An untrusted pointer dereference exists in the sideband streaming API. This issue allows an attacker to trigger an arbitrary memory dereference, which could lead to remote code execution. Exploitation is possible by providing a specially crafted
Moniker protobuf message.Recommendations
Update to a version later than 2.17.0.
Fix
RCE
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grpc-Device