First published: Thu Apr 21 2022(Updated: )
There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NI FlexLogger | =2021-r2 | |
NI FlexLogger | =2021-r3 | |
NI FlexLogger | =2021-r4 | |
Ni G Web Development Software | =2021 | |
Ni G Web Development Software | =2021 | |
NI LabVIEW | =2021 | |
NI LabVIEW | =2021 | |
Ni Static Test Software Suite | <1.2 | |
NI SystemLink | =2020-r4 | |
NI SystemLink | =2022-r1 | |
NI SystemLink | =2022-r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27237 is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products.
The severity of CVE-2022-27237 is medium with a CVSS score of 6.1.
The NI products affected by CVE-2022-27237 include Ni Flexlogger, Ni G Web Development Software, Ni Labview, Ni Static Test Software Suite, and Ni Systemlink.
To fix CVE-2022-27237, you should install the recommended updates for the affected NI products.
You can find more information about CVE-2022-27237 at the following link: https://www.ni.com/en-us/support/documentation/supplemental/22/cross-site-scripting-vulnerability--in-ni-web-server-component.html