PT-2023-29793 · National Instruments · Ni System Configuration
Published
2023-10-18
·
Updated
2023-10-28
·
CVE-2023-4601
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NI System Configuration versions prior to 2023 Q3
Description
A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response.
Recommendations
For versions prior to 2023 Q3, update to a version newer than 2023 Q3 to resolve the issue. As a temporary workaround, consider restricting access to the NI System Configuration to minimize the risk of exploitation.
Fix
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ni System Configuration