We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6638

Integer Overflow Vulnerability Reading TDMS Files in LabVIEW



AssignerNI
Reserved2024-07-09
Published2024-07-22
Updated2024-08-01

Description

An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1 and prior versions.



MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-190 Integer Overflow or Wraparound

Product status

Default status
unaffected

Any version
affected

Credits

James McNally of Wiresmith Technology 0x400543ecd0

References

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/integer-overflow-vulnerability-reading-tdms-files-in-labview.html

cve.org CVE-2024-6638

nvd.nist.gov CVE-2024-6638

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.