CVE Vulnerabilities

CVE-2023-4570

Unprotected Alternate Channel

Published: Oct 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the ni-measurementlink-service Python package and all previous versions.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Affected Software

Name Vendor Start Version End Version
Measurementlink Ni 1.0.0 (including) 1.1.1 (excluding)

Potential Mitigations

References