ZDI-CAN-21802: ZDI-24-1032: NI FlexLogger Redis Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of NI FlexLogger. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-6121.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21802?
The severity of ZDI-CAN-21802 is rated 7.8 based on the CVSS scoring system.
How do I fix ZDI-CAN-21802?
To fix ZDI-CAN-21802, patch your NI FlexLogger installation with the latest updates provided by National Instruments.
What type of attack does ZDI-CAN-21802 exploit?
ZDI-CAN-21802 allows local attackers to escalate privileges on affected installations of NI FlexLogger.
What is required for an attacker to exploit ZDI-CAN-21802?
An attacker must first gain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-21802.
Which software is affected by ZDI-CAN-21802?
The vulnerable software affected by ZDI-CAN-21802 is NI FlexLogger.