CRITICAL
Stack-based Buffer Overflow in NI System Configuration Software
Published Oct 18, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.62%
Description
A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response. This affects NI System Configuration 2023 Q3 and all previous versions.
Affected products
-
- Version 0StatusaffectedConstraints<=23.5.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NI | System Configuration | unaffected |
|
AND
OR
- < 2023
- 2023
- 2023
-
- Version 0StatusaffectedConstraints<=23.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NI | System Configuration | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54454 Advisory
- https://www.ni.com/en/support/documentation/supplemental/23/stack-based-buffer-overflow-in-ni-system-configuration.html MitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54454 | Advisory | |
| https://www.ni.com/en/support/documentation/supplemental/23/stack-based-buffer-overflow-in-ni-system-configuration.html | MitigationVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NI
Published Oct 18, 2023
Updated Sep 13, 2024
Reserved Aug 29, 2023
Link CVE-2023-4601
CISA Vulnrichment
Updated Sep 13, 2024
ENISA EUVD
EUVD-2023-54454 Assigner NI
Published Oct 18, 2023
Updated Sep 13, 2024
Exploited since n/a
Link EUVD-2023-54454