CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-9142

CVSS 9.3v4.0pub. 2026-06-19upd. 2026-06-25

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthenticated user access to the server on the local network.  This affects NI grpc-device 2.17.0 and prior versions.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ni Instrumentstudio

    APP
    Ni
    2026≤ 2025
  • Ni Grpc Device Server

    APP
    Ni
    < 2.18.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-48137CRITICAL9.3PL ✓same product

RCE przez untrusted pointer dereference w NI grpc-device sideband streaming API

CVE-2026-48138HIGH8.7same product

There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check...

CVE-2026-48139HIGH8.7same product

There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow...

CVE-2026-48140HIGH7.1same product

There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker...

CVE-2026-48141MEDIUM6.0same product

W module NI grpc-device BeginSidebandStream występuje wyciek pamięci, który może prowadzić do denial of servic...