CVE-2022-27237: XSS
There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-27237?
CVE-2022-27237 is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products.
What is the severity of CVE-2022-27237?
The severity of CVE-2022-27237 is medium with a CVSS score of 6.1.
Which NI products are affected by CVE-2022-27237?
The NI products affected by CVE-2022-27237 include Ni Flexlogger, Ni G Web Development Software, Ni Labview, Ni Static Test Software Suite, and Ni Systemlink.
How can I fix CVE-2022-27237?
To fix CVE-2022-27237, you should install the recommended updates for the affected NI products.
Where can I find more information about CVE-2022-27237?
You can find more information about CVE-2022-27237 at the following link: https://www.ni.com/en-us/support/documentation/supplemental/22/cross-site-scripting-vulnerability--in-ni-web-server-component.html