PT-2023-29793 · National Instruments · Ni System Configuration

CVE-2023-4601

·

Published

2023-10-18

·

Updated

2023-10-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NI System Configuration versions prior to 2023 Q3
Description A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response.
Recommendations For versions prior to 2023 Q3, update to a version newer than 2023 Q3 to resolve the issue. As a temporary workaround, consider restricting access to the NI System Configuration to minimize the risk of exploitation.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4601
ZDI-23-1568

Affected Products

Ni System Configuration