CVE-2024-12740
Vision related software from NI used a third-party library for image processing that exposes several vulnerabilities. These vulnerabilities may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted file.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N
- EPSS probability
- 0.19%
- CWE
- CWE-1395
- Published
- 2025-01-27
- Last modified
- 2026-03-13
Affected products
- NI Vision Development Module
- NI FlexRIO
- NI NI-IMAQdx
- NI Vision Acquisition Software
- NI Vision Builder for Automated Inspection
- NI Data Record AD
- NI FRC Game Tools
Weakness type
Related vulnerabilities
- CVE-2026-69713 — Windows Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-58235 — Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
- CVE-2026-58586 — Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2026-47906 — Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2026-8993 — Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
- CVE-2025-31973 — HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'