National Instruments · Ni Systemlink Server · CVE-2024-6122
Name of the Vulnerable Software and Affected Versions:
NI SystemLink Server versions prior to 2024 Q1
NI FlexLogger versions prior to 2023 Q2
Description:
An issue with incorrect permissions in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may lead to information disclosure via local access.
Recommendations:
For NI SystemLink Server versions prior to 2024 Q1, update to a version 2024 Q1 or later.
For NI FlexLogger versions prior to 2023 Q2, update to a version 2023 Q2 or later.
As a temporary workaround, consider restricting access to the KeyValueDatabase service to minimize the risk of exploitation.