Impact
NI SystemLink and its Server component store sensitive credentials or tokens in cleartext, allowing a local attacker to read and expose these unencrypted secrets. The flaw directly compromises confidentiality and is classified as CWE‑312. The vulnerability affects all releases prior to 2026 Q3.
Affected Systems
The flaw exists in NI SystemLink and NI SystemLink Server in all releases prior to 2026 Q3. All earlier versions before 2026 Q3 are affected.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity flaw. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the local‑access requirement means that insiders or compromised local accounts can readily exploit the defect. Once local privileges are achieved, reading the cleartext store is straightforward, with no additional network or privilege escalation steps required.
OpenCVE Enrichment