Описание
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthenticated user access to the server on the local network. This affects NI grpc-device 2.17.0 and prior versions.
Уязвимые конфигурации
Конфигурация 1Версия до 2025 (включая)
Одно из
cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:*
cpe:2.3:a:ni:instrumentstudio:2026:q1:*:*:*:*:*:*
cpe:2.3:a:ni:instrumentstudio:2026:q2:*:*:*:*:*:*
Конфигурация 2Версия до 2.18.0 (исключая)
cpe:2.3:a:ni:ni_grpc_device_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00434
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-306
EPSS
Процентиль: 37%
0.00434
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-306