Memory Corruption Flaw in NI Circuit Design Suite by National Instruments
CVE-2025-30417

8.5HIGH

Key Information:

Vendor

Ni

Vendor
CVE Published:
15 May 2025

What is CVE-2025-30417?

A memory corruption vulnerability exists in the Library!DecodeBase64() function triggered when using the SymbolEditor in the NI Circuit Design Suite. This flaw can lead to information disclosure or arbitrary code execution. An attacker could exploit this vulnerability by convincing a user to open a specially crafted .sym file, potentially compromising the user's system. The vulnerability impacts NI Circuit Design Suite version 14.3.0 and all earlier versions.

Affected Version(s)

Circuit Design Suite 0 <= 14.3.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl working with CISA
.