PT-2023-29652 · National Instruments · Ni-Measurementlink-Service
Published
2023-10-05
·
Updated
2023-10-12
·
CVE-2023-4570
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ni-measurementlink-service versions 1.1.0 and earlier
Description
An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node.
Recommendations
For versions 1.1.0 and earlier, upgrade to version 1.1.1 or later of the ni-measurementlink-service Python package to resolve the issue. As a temporary workaround, consider restricting access to the services exposed on localhost to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ni-Measurementlink-Service