Path Traversal Vulnerabilities in National Instruments Software and ABB DataManager
CVE-2013-5021

Currently unrated

Key Information:

Vendor

Ni

Vendor
CVE Published:
6 August 2013

What is CVE-2013-5021?

Multiple absolute path traversal vulnerabilities exist in the ActiveX controls within National Instruments' cwui.ocx, affecting several products including LabWindows/CVI and LabVIEW. These vulnerabilities allow remote attackers to leverage the ExportStyle method, enabling them to create and execute arbitrary files on affected systems by manipulating path names in certain argument properties. The issue is particularly impactful in products that utilize properties such as Caption or FormatString, which can lead to unauthorized file access and execution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.