ZDI-24-1033: NI FlexLogger Redis Server Incorrect Permission Assignment Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of NI FlexLogger. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2024-6122.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1033?
The severity of ZDI-24-1033 is determined by the CVSS score assigned by the Zero Day Initiative, which indicates a moderate risk.
How do I fix ZDI-24-1033?
To fix ZDI-24-1033, update your NI FlexLogger software to the latest version provided by National Instruments.
Who is affected by ZDI-24-1033?
ZDI-24-1033 affects installations of NI FlexLogger that allow local attackers to execute low-privileged code.
What type of information is disclosed by ZDI-24-1033?
ZDI-24-1033 allows local attackers to disclose sensitive information that could lead to further exploitation of the system.
Can ZDI-24-1033 be exploited remotely?
No, ZDI-24-1033 requires local access to the system to exploit the vulnerability.