Impact
This vulnerability is a memory corruption issue caused by an out‑of‑bounds write that occurs when Digilent DASYLab opens a corrupted .DSB file. The flaw can lead to information disclosure or arbitrary code execution, as indicated by the vulnerability description and the CVE score of 8.5. It is characterized by CWE‑787."
Affected Systems
All versions of Digilent DASYLab are affected. The affected product is listed in the vendor/product list as Digilent:DASYLab and the CPE string cpe:2.3:a:ni:dasylab:*:*:*:*:*:*:*:* indicates a broad application across all releases.
Risk and Exploitability
The CVSS score of 8.5 denotes high severity, but the EPSS score is reported as less than 1%, suggesting low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a specially crafted .DSB file and convince a user to open it, indicating that user interaction is a prerequisite for success. Because of the high impact and user‑dependent attack vector, the overall risk can be considered moderate with a clear potential for severe compromise if an exploit is delivered to an end‑user.
OpenCVE Enrichment