Back to overview

CVE-2026-48137

CRITICAL
9.1
CVSS 3.1
Description
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution.  Successful exploitation requires an attacker  to supply a specially crafted Moniker protobuf message.  This affects NI grpc-device 2.17.0 and prior versions.

Metadata

CVE ID
CVE-2026-48137
State
PUBLISHED
Assigner
NI
Reserved
2026-05-20 19:51 UTC
Published
2026-06-19 13:05 UTC
Last updated
2026-06-19 13:18 UTC
Primary CWE
CWE-822
CWE-822 Untrusted pointer dereference
Vendor / Product
NI / grpc-device
Sources
cve.org  ·  NVD

Severity & Metrics

9.1 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products (2)
VendorProductPlatformVersions
NI grpc-device 0 ≤ 2.17.0
NI InstrumentStudio 0 ≤ 26.3.0
Weakness (CWE)
CWESourceDescription
CWE-822 cna CWE-822 Untrusted pointer dereference
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
9.1 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Back to overview