CVE-2026-48137

CRITICAL

Untrusted pointer dereference in NI grpc-device sideband streaming API

Title source: cna
STIX 2.1

Description

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution.  Successful exploitation requires an attacker  to supply a specially crafted Moniker protobuf message.  This affects NI grpc-device 2.17.0 and prior versions.

Scores

CVSS v3 9.1
EPSS 0.0056
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-822
Status published
Products (5)
NI/grpc-device < 2.17.0
ni/instrumentstudio 2026 q1 (2 CPE variants)
ni/instrumentstudio < 2025
NI/InstrumentStudio < 26.3.0
ni/ni_grpc_device_server < 2.18.0
Published Jun 19, 2026
Tracked Since Jun 19, 2026