CVE Vulnerabilities

CVE-2023-4570

Unprotected Alternate Channel

Published: Oct 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the ni-measurementlink-service Python package and all previous versions.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Affected Software

NameVendorStart VersionEnd Version
MeasurementlinkNi1.0.0 (including)1.1.1 (excluding)

Potential Mitigations

References