A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions. Please note that DAQExpress is an EOL product and will not receive any updates.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 06 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Deserialization Of Untrusted Data Vulnerability In NI DAAQAExpress Project File | Deserialization Of Untrusted Data Vulnerability In NI DAQExpress Project File |
Wed, 18 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Dec 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions. Please note that DAQExpress is an EOL product and will not receive any updates. | |
| Title | Deserialization Of Untrusted Data Vulnerability In NI DAAQAExpress Project File | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published: 2024-12-18T19:20:41.889Z
Updated: 2025-03-06T16:18:31.635Z
Reserved: 2024-12-17T20:53:13.401Z
Link: CVE-2024-12741
Updated: 2024-12-18T19:41:47.124Z
Status : Received
Published: 2024-12-18T20:15:22.390
Modified: 2024-12-18T20:15:22.390
Link: CVE-2024-12741
No data.