Numeric Types Conversion Vulnerability in NI grpc-device Software
CVE-2026-9143

6.3MEDIUM

Key Information:

Vendor

Ni

Vendor
CVE Published:
19 June 2026

What is CVE-2026-9143?

A vulnerability exists in NI grpc-device, where improper conversion between numeric types can occur due to missing range checks in the CodeGen component. This flaw has the potential to silently discard significant high bits if a size value exceeds the allowable range of the target type, which can lead to unintended behavior and potentially compromise the integrity of user data. This issue affects all versions of NI grpc-device up to and including 2.17.0.

Affected Version(s)

grpc-device 0 <= 2.17.0

InstrumentStudio 0 <= 26.3.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sebastián Alba Vives (@Sebasteuo / 0xS4bb1)
.