There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthenticated user access to the server on the local network. This affects NI grpc-device 2.17.0 and prior versions.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthenticated user access to the server on the local network. This affects NI grpc-device 2.17.0 and prior versions. | |
| Title | Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present | |
| First Time appeared |
Ni
Ni grpc-device Ni instrumentstudio |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:ni:grpc-device:*:*:*:*:*:*:*:* cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ni
Ni grpc-device Ni instrumentstudio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NI
Published:
Updated: 2026-06-19T13:41:26.730Z
Reserved: 2026-05-20T19:51:58.847Z
Link: CVE-2026-9142
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses