CVE-2024-12740
Dependency on Vulnerable Third-Party Component exposes Vulnerabilities in NI Vision Software
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vision related software from NI used a third-party library for image processing that exposes several vulnerabilities. These vulnerabilities may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted file.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of JPG files referenced from a VBAI file. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-12-17 CVE Reserved
- 2025-01-27 CVE Published
- 2025-02-03 CVE Updated
- 2025-04-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1395: Dependency on Vulnerable Third-Party Component
CAPEC
- CAPEC-23: File Content Injection
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
NI Search vendor "NI" | Vision Development Module Search vendor "NI" for product "Vision Development Module" | <= 24.1 Search vendor "NI" for product "Vision Development Module" and version " <= 24.1" | en |
Affected
| ||||||
NI Search vendor "NI" | FlexRIO Search vendor "NI" for product "FlexRIO" | < 25.0 Search vendor "NI" for product "FlexRIO" and version " < 25.0" | en |
Affected
| ||||||
NI Search vendor "NI" | NI-IMAQdx Search vendor "NI" for product "NI-IMAQdx" | <= 23.1 Search vendor "NI" for product "NI-IMAQdx" and version " <= 23.1" | en |
Affected
| ||||||
NI Search vendor "NI" | Vision Acquisition Software Search vendor "NI" for product "Vision Acquisition Software" | <= 23.1 Search vendor "NI" for product "Vision Acquisition Software" and version " <= 23.1" | en |
Affected
| ||||||
NI Search vendor "NI" | Vision Builder For Automated Inspection Search vendor "NI" for product "Vision Builder For Automated Inspection" | <= 23.* Search vendor "NI" for product "Vision Builder For Automated Inspection" and version " <= 23.*" | en |
Affected
| ||||||
NI Search vendor "NI" | Data Record AD Search vendor "NI" for product "Data Record AD" | <= 2.0 Search vendor "NI" for product "Data Record AD" and version " <= 2.0" | en |
Affected
| ||||||
NI Search vendor "NI" | FRC Game Tools Search vendor "NI" for product "FRC Game Tools" | <= 25.0 Search vendor "NI" for product "FRC Game Tools" and version " <= 25.0" | en |
Affected
|