Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions. | |
| Title | Untrusted pointer dereference in NI grpc-device sideband streaming API | |
| First Time appeared |
Ni
Ni grpc-device Ni instrumentstudio |
|
| Weaknesses | CWE-822 | |
| CPEs | cpe:2.3:a:ni:grpc-device:*:*:*:*:*:*:*:* cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ni
Ni grpc-device Ni instrumentstudio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published:
Updated: 2026-06-22T16:15:01.777Z
Reserved: 2026-05-20T19:51:56.935Z
Link: CVE-2026-48137
Updated: 2026-06-22T16:14:57.545Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-19T22:00:06Z