PT-2025-1943 · National Instruments · Ni Vision Development Module+1

Kimiya

·

Published

2025-01-27

·

Updated

2025-02-03

·

CVE-2024-12740

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NI Vision Builder AI (affected versions not specified) NI Vision Development Module (affected versions not specified)
Description The issue is related to the use of a third-party library for image processing in NI's vision software, which exposes several vulnerabilities. These vulnerabilities may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted file.
Recommendations For NI Vision Builder AI, update to a version that does not use the vulnerable third-party library for image processing. For NI Vision Development Module, update to a version that does not use the vulnerable third-party library for image processing. As a temporary workaround, consider restricting the opening of specially crafted files until a patch is available. Avoid using the vulnerable library for image processing in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-12740
ZDI-25-077
ZDI-25-078
ZDI-25-079
ZDI-25-080

Affected Products

Ni Vision Builder Ai
Ni Vision Development Module