National Instruments LabVIEW
National Instruments LabVIEW versions 24.1f0 and earlier contain two memory safety vulnerabilities: an out-of-bounds read due to missing bounds checking (CWE-125) and memory corruption issues due to improper length checks (CWE-119). Both vulnerabilities are local in nature and require user interaction, such as opening a malicious LabVIEW project file. Successful exploitation allows a local attacker to disclose sensitive information from process memory and execute arbitrary code with the privileges of the LabVIEW application.
- Local access to the LabVIEW system
- User interaction required (likely opening a malicious file or project)
- LabVIEW version 24.1f0 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b6ade5fa-c0b6-4408-a494-ac3ebe79cd32Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.