Deserialization of Untrusted Data Vulnerability in FlexLogger and InstrumentStudio
Published May 10, 2024
7.8
HIGHCVSS 3.1
EPSS 14.69%
Description
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior versions as well as NI InstrumentStudio 2024 Q1 and prior versions.
Affected products
-
Affected
- ≥ 0, ≤ 24.1
-
Affected
- ≥ 0, ≤ 24.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NI | FlexLogger | unaffected | Affected
|
| NI | InstrumentStudio | unaffected | Affected
|
No data.
-
Affected
- ≥ 2024, ≤ 24.1
-
Affected
- ≥ 2024, ≤ 24.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NI | Flexlogger | unaffected | Affected
|
| NI | Instrumentstudio | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data