7.8

CVE-2024-23612

Improper Error Handling Issue in LabVIEW

An improper error handling vulnerability in LabVIEW may result in remote code execution.  Successful exploitation requires an attacker to provide a user with a specially crafted VI.  This vulnerability affects LabVIEW 2024 Q1 and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Labview Version <= 2020
Ni ≫ Labview Version 2021 Update - SwEdition -
Ni ≫ Labview Version 2021 Update sp1
Ni ≫ Labview Version 2022 Update q1
Ni ≫ Labview Version 2022 Update q3
Ni ≫ Labview Version 2023 Update q1
Ni ≫ Labview Version 2023 Update q3
Ni ≫ Labview Version 2023 Update q3_patch1
Ni ≫ Labview Version 2023 Update q3_patch2
Ni ≫ Labview Version 2024 Update q1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.442
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input

The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/improper-error-handling-issues-in-labview.html
Vendor Advisory