PT-2024-37792 · National Instruments · Ni Veristand

Kimiya

·

Published

2024-07-22

·

Updated

2024-07-30

·

CVE-2024-6675

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NI VeriStand versions prior to 2024 Q2
Description A deserialization of untrusted data issue exists, potentially leading to remote code execution. Successful exploitation requires an attacker to trick a user into opening a specially crafted project file.
Recommendations For versions prior to 2024 Q2, avoid opening project files from untrusted sources until a fix is available. As a temporary workaround, consider restricting access to project files to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6675
ZDI-24-1031

Affected Products

Ni Veristand