Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
📦
ni-pal
Vendor: ni
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
5
Total Indexed
Avg. EPSS
0.21%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
8.4
CVSS
Severity: HIGH
6.9
CVSS
Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
Severity: MEDIUM
7.8
CVSS
CVE-2021-38304
Exploit Found
Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.
Severity: HIGH