This page provides information about published security advisories for NI software in 2025. Click the link in the Info Code column to obtain more information or to download the update.
| Name | Type | Description | Info Code |
|---|---|---|---|
| NI Security Update for CVE-2024-12740 | Software | NI’s vision related software uses a third-party library for image processing that exposes several vulnerabilities. These vulnerabilities may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted file. | CVE-2024-12740 |
| Name | Type | Description | Info Code |
|---|---|---|---|
| NI Security Update for CVE-2025-2631 and CVE-2025-2632 | Software | There are two out of bounds write vulnerabilities due to improper bounds checking that exist in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. | CVE-2025-2631 and CVE-2025-2632 |
| NI Security Update for CVE-2025-2630 | Software | There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. | CVE-2025-2630 |
| NI Security Update for CVE-2025-2629 | Software | There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. | CVE-2025-2629 |
| Name | Type | Description | Info Code |
|---|---|---|---|
| NI Security Update for CVE-2025-30417, CVE-2025-30418, CVE-2025-30419, CVE-2025-30420, and CVE-2025-30421 | Software | There are several memory corruption vulnerabilities due to improper bounds checking that exist in the Symbol Editor included with NI Circuit Design Suite. These vulnerabilities may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. These vulnerabilities affect NI Circuit Design Suite 14.3.0 and prior versions. | CVE-2025-30417 CVE-2025-30418 CVE-2025-30419 CVE-2025-30420 CVE-2025-30421 |
| Name | Type | Description | Info Code |
|---|---|---|---|
| NI Security Update for CVE-2025-7361 | Software | A code injection vulnerability using an exposed function exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI that contains a Code Interface Node (CIN). This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions. LabVIEW 64-bit versions do not support CIN nodes and are not affected. | CVE-2025-7361 |
| NI Security Update for CVE-2025-7848 and CVE-2025-7849 | Software | There are two memory corruption vulnerabilities due to improper error handling that exist in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. These vulnerabilities affect NI LabVIEW 2025 Q1 and prior versions. | CVE-2025-7848 CVE-2025-7849 |
| NI Security Update for CVE-2025-2633 and CVE-2025-2634 | Software | There are two out of bounds read vulnerabilities due to improper bounds checking that exist in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. These vulnerabilities affect NI LabVIEW 2025 Q1 and prior versions. | CVE-2025-2633 CVE-2025-2634 |
| Name | Type | Description | Info Code |
|---|---|---|---|
| NI Security Update for CVE-2025-9188, CVE-2025-9189, CVE-2025-57774, CVE-2025-57775, CVE-2025-57776, CVE-2025-57777, and CVE-2025-57778 | Software | There are multiple vulnerabilities related to improper validation when parsing DSB files in Digilent DASYLab that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. These vulnerabilities affect all versions of Digilent DASYLab. | CVE-2025-9188 CVE-2025-9189 CVE-2025-57774 CVE-2025-57775 CVE-2025-57776 CVE-2025-57777 CVE-2025-57778 |
| Name | Type | Description | Info Code |
|---|---|---|---|
| NI Security Update for CVE-2025-2449 | Software | There is a relative file path directory traversal vulnerability in the USI Registration tool for DataPlugins (USIReg.exe) used by NI software that may result in arbitrary code execution. The USI Registration tool is used to install DataPlugins for use by other NI Software. Successful exploitation requires an attacker to get a user to open a specially crafted .uri file. | CVE-2025-2449 |
| NI Security Update for CVE-2025-10203 | Software | There is a relative file path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent WaveForms 3.24.3 and prior versions. | CVE-2025-10203 |
| NI Security Update for CVE-2025-6033 and CVE-2025-6034 | Software | There are two memory corruption vulnerabilities due to improper input validation that exist in the Symbol Editor included with NI Circuit Design Suite. These vulnerabilities may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. | CVE-2025-6033 CVE-2025-6034 |