NI grpc-device是美国NI公司的一个基于gRPC协议的服务器,它让用户能够通过网络远程调用NI硬件设备的驱动API,而不需要在本地安装NI的驱动软件或硬件。 NI grpc-device 2.17.0及之前版本存在处理逻辑错误漏洞,该漏洞源于BeginSidebandStream中存在未检查的枚举类型转换,可能导致攻击者触发无效枚举状态和未定义行为,造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NI | grpc-device | ≤ 2.17.0 |
affected |
| NI | InstrumentStudio | ≤ 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NI | grpc-device | 0 ~ 2.17.0 | - |
|
| NI | InstrumentStudio | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48137 | 9.1 CRITICAL | Untrusted pointer dereference in NI grpc-device sideband streaming API |
| CVE-2026-9142 | 9.1 CRITICAL | Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not |
| CVE-2026-48138 | 7.5 HIGH | Out-of-bounds read vulnerability in the NI grpc-device streaming API |
| CVE-2026-48139 | 7.5 HIGH | NULL pointer dereference vulnerability in NI grpc-device data moniker service |
| CVE-2026-48141 | 5.3 MEDIUM | Memory leak in NI grpc-device BeginSidebandStream |
| CVE-2026-9143 | 3.7 LOW | Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks i |
No comments yet