NI VeriStand是美国国家仪器(NI)公司的一款用于实时测试应用的软件。可以通过模型集成、实时激励生成和可扩展的软件环境,加快产品开发生命周期。 NI VeriStand 2024 Q2版本及之前版本存在安全漏洞。攻击者利用该漏洞可以远程执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6794 | 9.8 CRITICAL | Deserialization of Untrusted Data in NI VeriStand Waveform Streaming Server |
| CVE-2024-6806 | 9.8 CRITICAL | Missing Authorization Checks In NI VeriStand Gateway For Project Resources |
| CVE-2024-6791 | 7.8 HIGH | Directory Path Traversal Vulnerability in NI VeriStand with vsmodel Files |
| CVE-2024-6121 | 7.8 HIGH | NI SystemLink Server Ships Out of Date Redis Version |
| CVE-2024-6675 | 7.8 HIGH | Deserialization of Untrusted Data Vulnerability in NI VeriStand Project File |
| CVE-2024-6805 | 7.5 HIGH | Missing Authorization Checks in NI VeriStand Gateway for File Transfer Resources |
| CVE-2024-6122 | 5.5 MEDIUM | Incorrect Default Directory Permissions for NI SystemLink Redis Service |
| CVE-2024-6638 | 5.5 MEDIUM | Integer Overflow Vulnerability Reading TDMS Files in LabVIEW |
No comments yet