A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.
The vulnerability results from improper handling of data deserialization incoming through the DataLogging Server component in NI VeriStand. An attacker can send a specially crafted network message to the vulnerable server, which leads to deserialization of malicious data and consequently to execution of arbitrary code. The attack requires no authentication or user interaction, and low complexity threshold makes it particularly dangerous.
Successful exploitation allows an attacker to execute code remotely (RCE) with the privileges of the DataLogging Server process, which can lead to complete system takeover, loss of data confidentiality and integrity, and disruption of service availability.
Apply patches available from the manufacturer according to references — updates are described on the NI website at: https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/deserialization-of-untrusted-data-vulnerabilities-in-ni-veristand.html. Until patches are applied, it is recommended to restrict network access to the DataLogging Server component using firewall or network segmentation.
NI VeriStand 2024 Q2 and all earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNi Veristand
APPNi2024≤ 2024
Related vulnerabilities
RCE przez deserializację danych w NI VeriStand Waveform Streaming Server
Brak weryfikacji autoryzacji w NI VeriStand Gateway — RCE
A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in...
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resour...
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure...