National Instruments

First CVE: Oct 5, 2023Active for: 3 years
83
CVEs Published
More CVEs Published than 68% of tracked CNAs
20.8
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by National Instruments as a CNA, 89.2% affect products that National Instruments develops as a vendor.

89.2%
10.8%
Self-reported: 74Third-party: 9

Of all the CVEs published that affect products developed by National Instruments, 82.2% are self-published by National Instruments as a CNA.

82.2%
17.8%
Self-published: 74Published by other CNAs: 16

Trends Over Time

The number and severity of CVEs published by National Instruments over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2023
2 years ago
Most Recent CVE
Jun 19, 2026
35 days ago

Top CVEs

All CVEs published by National Instruments as a CNA, regardless of affected vendor or product.

83 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentiall
Jun 19, 20269.839NONO
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthent
Jun 19, 20269.138NONO
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication con
May 29, 20269.138NONO
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects
Jun 2, 20267.833NONO
There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash.  Succ
Jun 19, 20267.530NONO
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requi
Jun 19, 20267.530NONO
A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker
Jul 22, 20249.830NONO
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affect
Jul 22, 20249.829NONO
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation r
May 14, 20247.829NONO
There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion.  This affects NI grpc-device 2.17.0 and prior versions.
Jun 19, 20267.528NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA83 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local68 (81.9%)
Network14 (16.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.2%)
Attack Complexity
Low83 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None28 (33.7%)
Unknown0 (0.0%)
Required55 (66.3%)
Privileges Required
Low14 (16.9%)
High0 (0.0%)
None69 (83.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (83 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by National Instruments as a CNA.

Media Mentions

Media articles that mention a CVE ID published by National Instruments as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs