CVE-2025-30421

There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ni:circuit_design_suite:*:*:*:*:*:*:*:*

History

20 May 2025, 15:45

Type Values Removed Values Added
CWE CWE-787
First Time Ni
Ni circuit Design Suite
CPE cpe:2.3:a:ni:circuit_design_suite:*:*:*:*:*:*:*:*
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-ni-circuit-design-suite.html - Vendor Advisory

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de corrupción de memoria debido a un desbordamiento de búfer basado en la pila en DrObjectStorage::XML_Serialize() al usar SymbolEditor en NI Circuit Design Suite. Esta vulnerabilidad puede provocar la divulgación de información o la ejecución de código arbitrario. Para explotarla con éxito, un atacante debe obligar al usuario a abrir un archivo .sym especialmente manipulado. Esta vulnerabilidad afecta a NI Circuit Design Suite 14.3.0 y versiones anteriores.

15 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 17:15

Updated : 2025-05-20 15:45


NVD link : CVE-2025-30421

Mitre link : CVE-2025-30421

CVE.ORG link : CVE-2025-30421


JSON object : View

Products Affected

ni

  • circuit_design_suite
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write