CVE-2024-6122

MEDIUM

NI SystemLink Server < 2024 Q1 - Information Disclosure via Incorrect Directory Permissions

Title source: llm
STIX 2.1

Description

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (4)
ni/flexlogger 2023 q2
ni/flexlogger < 2023
ni/systemlink 2024 q1
ni/systemlink < 2024
Published Jul 22, 2024
Tracked Since Feb 18, 2026