Description
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially crafted message containing an out-of-range value. This affects NI grpc-device 2.17.0 and prior versions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially crafted message containing an out-of-range value. This affects NI grpc-device 2.17.0 and prior versions. | |
| Title | Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream | |
| First Time appeared |
Ni
Ni grpc-device Ni instrumentstudio |
|
| Weaknesses | CWE-704 | |
| CPEs | cpe:2.3:a:ni:grpc-device:*:*:*:*:*:*:*:* cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ni
Ni grpc-device Ni instrumentstudio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published:
Updated: 2026-06-19T13:32:18.095Z
Reserved: 2026-05-20T19:51:56.936Z
Link: CVE-2026-48140
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-704
Incorrect Type Conversion or Cast