CVE-2025-9189
There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-1285
- Published
- 2025-09-02
- Last modified
- 2026-09-03
Affected products
- Digilent DASYLab
- measX DASYLab
Weakness type
Related vulnerabilities
- CVE-2025-3357 — IBM Tivoli Monitoring code execution
- CVE-2025-3755 — Information Disclosure and Denial-of-Service(DoS) Vulnerability in MELSEC iQ-F Series CPU module
- CVE-2024-36342 — Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in
- CVE-2023-46724 — SQUID-2023:4 Denial of Service in SSL Certificate validation
- CVE-2025-7849 — Memory Corruption Issue in NI LabVIEW due to improper error handling
- CVE-2025-7848 — Missing input check in lvpict.cpp used in NI LabVIEW
- CVE-2025-57778 — Out Of Bounds Write to invalid source address when parsing a DSB file with Digilent DASYLab
- CVE-2025-57777 — Out Of Bounds Write in displ2.dll when parsing a DSB file with Digilent DASYLab