PT-2024-37397 · National Instruments · Ni Systemlink Server+1

Published

2024-07-22

·

Updated

2024-09-12

·

CVE-2024-6121

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NI SystemLink Server versions 2024 Q1 and prior NI FlexLogger versions 2023 Q2 and prior
Description: The issue is related to an out-of-date version of Redis shipped with the affected software, which is susceptible to multiple vulnerabilities. This affects certain versions of NI SystemLink Server and NI FlexLogger.
Recommendations: For NI SystemLink Server versions 2024 Q1 and prior, update to a version that includes an updated Redis component to resolve the issue. For NI FlexLogger versions 2023 Q2 and prior, update to a version that includes an updated Redis component to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-6121
ZDI-24-1032

Affected Products

Ni Flexlogger
Ni Systemlink Server