There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions. | |
| Title | Untrusted pointer dereference in NI grpc-device sideband streaming API | |
| First Time appeared |
Ni
Ni grpc-device Ni instrumentstudio |
|
| Weaknesses | CWE-822 | |
| CPEs | cpe:2.3:a:ni:grpc-device:*:*:*:*:*:*:*:* cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ni
Ni grpc-device Ni instrumentstudio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NI
Published:
Updated: 2026-06-19T13:18:09.580Z
Reserved: 2026-05-20T19:51:56.935Z
Link: CVE-2026-48137
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses