NI grpc-device是美国NI公司的一个基于gRPC协议的服务器,它让用户能够通过网络远程调用NI硬件设备的驱动API,而不需要在本地安装NI的驱动软件或硬件。 NI grpc-device 2.17.0及之前版本存在数字错误漏洞,该漏洞源于CodeGen中缺少范围检查,导致数字类型之间的转换错误,如果大小值超过目标类型的范围,可能会静默丢弃高位。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NI | grpc-device | ≤ 2.17.0 |
affected |
| NI | InstrumentStudio | ≤ 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NI | grpc-device | 0 ~ 2.17.0 | - |
|
| NI | InstrumentStudio | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48137 | 9.1 CRITICAL | Untrusted pointer dereference in NI grpc-device sideband streaming API |
| CVE-2026-9142 | 9.1 CRITICAL | Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not |
| CVE-2026-48138 | 7.5 HIGH | Out-of-bounds read vulnerability in the NI grpc-device streaming API |
| CVE-2026-48139 | 7.5 HIGH | NULL pointer dereference vulnerability in NI grpc-device data moniker service |
| CVE-2026-48140 | 6.5 MEDIUM | Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream |
| CVE-2026-48141 | 5.3 MEDIUM | Memory leak in NI grpc-device BeginSidebandStream |
No comments yet