NI LabVIEW(National Instruments LabVIEW)是美国国家仪器(NI)公司的一个图形化程序编译平台。 NI LabVIEW 2024 Q1版本及之前版本存在安全漏洞,该漏洞源于在读取TDMS文件时输入验证不当,从而整数溢出导致无限循环。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6794 | 9.8 CRITICAL | Deserialization of Untrusted Data in NI VeriStand Waveform Streaming Server |
| CVE-2024-6793 | 9.8 CRITICAL | Deserialization of Untrusted Data in NI VeriStand DataLogging Server |
| CVE-2024-6806 | 9.8 CRITICAL | Missing Authorization Checks In NI VeriStand Gateway For Project Resources |
| CVE-2024-6791 | 7.8 HIGH | Directory Path Traversal Vulnerability in NI VeriStand with vsmodel Files |
| CVE-2024-6121 | 7.8 HIGH | NI SystemLink Server Ships Out of Date Redis Version |
| CVE-2024-6675 | 7.8 HIGH | Deserialization of Untrusted Data Vulnerability in NI VeriStand Project File |
| CVE-2024-6805 | 7.5 HIGH | Missing Authorization Checks in NI VeriStand Gateway for File Transfer Resources |
| CVE-2024-6122 | 5.5 MEDIUM | Incorrect Default Directory Permissions for NI SystemLink Redis Service |
No comments yet