PT-2020-16007 · National Instruments · National Instruments Compactrio Driver
Published
2020-12-11
·
Updated
2020-12-14
·
CVE-2020-25191
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
National Instruments CompactRIO Driver versions prior to 20.5
Description
The issue is related to incorrect default permissions for an API entry-point of a specific service. This allows a non-authenticated user to trigger a function that could remotely reboot the CompactRIO.
Recommendations
For Driver versions prior to 20.5, update to version 20.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the API entry-point to prevent non-authenticated users from triggering the reboot function.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
National Instruments Compactrio Driver