CVE-2026-48140: Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially crafted message containing an out-of-range value. This affects NI grpc-device 2.17.0 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48140?
The severity of CVE-2026-48140 is medium with a score of 6.5.
How do I fix CVE-2026-48140?
To fix CVE-2026-48140, update to the latest version of the National Instruments NI grpc-device that contains the security patch.
What kind of attack does CVE-2026-48140 potentially enable?
CVE-2026-48140 could potentially enable a denial of service attack through triggering invalid enum states.
What components are affected by CVE-2026-48140?
The NI grpc-device in the BeginSidebandStream function is affected by CVE-2026-48140.
What is the impact of exploiting CVE-2026-48140?
Exploiting CVE-2026-48140 may result in undefined behavior and a potential denial of service.