Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f48-9j7q-q2gv

Опубликовано: 05 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

NI MeasurementLink Python Services Improper Access Restriction vulnerability

Impact

An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the ni-measurementlink-service Python package and all previous versions.

Patches

Upgrade all Python measurement plug-ins to use ni-measurementlink-service version 1.1.1 or later.

References

Visit ni.com/info and enter the info code cve-2023-4570 for more information.

Пакеты

Наименование

ni-measurementlink-service

pip
Затронутые версииВерсия исправления

< 1.1.1

1.1.1

Наименование

ni-measurementlink-service

pip
Затронутые версииВерсия исправления

>= 1.2.0.dev0, < 1.2.0

1.2.0

EPSS

Процентиль: 30%
0.00113
Низкий

8.8 High

CVSS3

Дефекты

CWE-420

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the ni-measurementlink-service Python package and all previous versions.

EPSS

Процентиль: 30%
0.00113
Низкий

8.8 High

CVSS3

Дефекты

CWE-420