CVE-2025-12097: Relative Path Traversal Vulnerability in NI System Web Server
There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files. This vulnerability existed in the NI System Web Server 2012 and prior versions. It was fixed in 2013.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12097?
CVE-2025-12097 is classified as a medium severity vulnerability due to potential information disclosure risks.
How do I fix CVE-2025-12097?
To mitigate CVE-2025-12097, upgrade the NI System Web Server to a version later than 2013.
What kind of exposure does CVE-2025-12097 pose?
CVE-2025-12097 allows attackers to potentially read arbitrary files on the server, leading to sensitive information exposure.
Can CVE-2025-12097 be exploited remotely?
Yes, CVE-2025-12097 can be exploited remotely by sending specially crafted requests to the vulnerable NI System Web Server.
What software versions are affected by CVE-2025-12097?
CVE-2025-12097 affects NI System Web Server versions up to 2013.