CVE-2024-6638
MEDIUMLabVIEW < 2024 Q1 - Denial of Service via TDMS File Parsing
Title source: llmDescription
An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
References (1)
Core 1
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
5.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-190
Status
published
Products (4)
ni/labview
2022 q1 (4 CPE variants)
ni/labview
2023 q1 (6 CPE variants)
ni/labview
2024 q1 (2 CPE variants)
ni/labview
< 2021
Published
Jul 22, 2024
Tracked Since
Feb 18, 2026