NI grpc-device是美国NI公司的一个基于gRPC协议的服务器,它让用户能够通过网络远程调用NI硬件设备的驱动API,而不需要在本地安装NI的驱动软件或硬件。 NI grpc-device 2.17.0及之前版本存在资源管理错误漏洞,该漏洞源于BeginSidebandStream存在内存泄漏,可能导致内存耗尽拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NI | grpc-device | ≤ 2.17.0 |
affected |
| NI | InstrumentStudio | ≤ 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NI | grpc-device | 0 ~ 2.17.0 | - |
|
| NI | InstrumentStudio | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48137 | 9.1 CRITICAL | Untrusted pointer dereference in NI grpc-device sideband streaming API |
| CVE-2026-9142 | 9.1 CRITICAL | Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not |
| CVE-2026-48138 | 7.5 HIGH | Out-of-bounds read vulnerability in the NI grpc-device streaming API |
| CVE-2026-48139 | 7.5 HIGH | NULL pointer dereference vulnerability in NI grpc-device data moniker service |
| CVE-2026-48140 | 6.5 MEDIUM | Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream |
| CVE-2026-9143 | 3.7 LOW | Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks i |
No comments yet