Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthenticated user access to the server on the local network. This affects NI grpc-device 2.17.0 and prior versions. | |
| Title | Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present | |
| First Time appeared |
Ni
Ni grpc-device Ni instrumentstudio |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:ni:grpc-device:*:*:*:*:*:*:*:* cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ni
Ni grpc-device Ni instrumentstudio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published:
Updated: 2026-06-22T19:29:31.269Z
Reserved: 2026-05-20T19:51:58.847Z
Link: CVE-2026-9142
Updated: 2026-06-22T19:29:27.737Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:36:11Z