First published: Thu May 15 2025(Updated: )
There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
NI Circuit Design Suite | <14.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30420 has a high severity due to potential information disclosure and arbitrary code execution.
To fix CVE-2025-30420, update the NI Circuit Design Suite to the latest version, beyond 14.3.0.
CVE-2025-30420 affects the NI Circuit Design Suite versions below 14.3.0.
Exploitation of CVE-2025-30420 can lead to either information disclosure or arbitrary code execution.
The vendor, NI, is responsible for providing patches and updates to mitigate CVE-2025-30420.