CVE-2020-25191

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2020
Last modified:
14/12/2020

Description

Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ni:compactrio_firmware:*:*:*:*:*:*:*:* 20.5 (excluding)
cpe:2.3:h:ni:compactrio:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools