CVE-2026-48140
MEDIUMNI grpc-device <= 2.17.0 BeginSidebandStream - Denial of Service
Title source: manualDescription
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially crafted message containing an out-of-range value. This affects NI grpc-device 2.17.0 and prior versions.
Scores
CVSS v3
6.5
EPSS
0.0044
EPSS Percentile
36.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-704
Status
published
Products (5)
NI/grpc-device
< 2.17.0
ni/instrumentstudio
2026 q1 (2 CPE variants)
ni/instrumentstudio
< 2025
NI/InstrumentStudio
< 26.3.0
ni/ni_grpc_device_server
< 2.18.0
Published
Jun 19, 2026
Tracked Since
Jun 19, 2026