8.5

CVE-2025-7361

Medienbericht

Code Injection Vulnerability in NI LabVIEW when using CIN nodes

A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node.  This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions.  LabVIEW 64-bit versions do not support CIN nodes and are not affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Labview Version <= 2021
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2022 Update q1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2022 Update q3
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2022 Update q3_patch1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2022 Update q3_patch2
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2022 Update q3_patch4
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2022 Update q3_patch5
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3_patch1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3_patch2
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3_patch3
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3_patch4
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3_patch5
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2023 Update q3_patch6
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2024 Update q1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2024 Update q1_patch1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2024 Update q3
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2024 Update q3_patch1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2024 Update q3_patch2
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2024 Update q3_patch3
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2025 Update q1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2025 Update q1_patch1
   Microsoft ≫ Windows Version - HwPlatform x86
Ni ≫ Labview Version 2025 Update q1_patch2
   Microsoft ≫ Windows Version - HwPlatform x86
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.194
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@ni.com 8.5 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/code-injection-vulnerability-in-ni-labview-using-cin-nodes.html
Vendor Advisory