A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions.  Please note that DAQExpress is an EOL product and will not receive any updates.
History

Thu, 06 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Title Deserialization Of Untrusted Data Vulnerability In NI DAAQAExpress Project File Deserialization Of Untrusted Data Vulnerability In NI DAQExpress Project File

Wed, 18 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
Description A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions.  Please note that DAQExpress is an EOL product and will not receive any updates.
Title Deserialization Of Untrusted Data Vulnerability In NI DAAQAExpress Project File
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published: 2024-12-18T19:20:41.889Z

Updated: 2025-03-06T16:18:31.635Z

Reserved: 2024-12-17T20:53:13.401Z

Link: CVE-2024-12741

cve-icon Vulnrichment

Updated: 2024-12-18T19:41:47.124Z

cve-icon NVD

Status : Received

Published: 2024-12-18T20:15:22.390

Modified: 2024-12-18T20:15:22.390

Link: CVE-2024-12741

cve-icon Redhat

No data.