CVE-2026-9143 Details
Description
There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a size value exceeded the target type's range. This affects NI grpc-device 2.17.0 and prior versions.
A vulnerability exists in NI gRPC Device Server in versions through 2.17.0, due to an incorrect conversion between numeric types. This issue arises from missing range checks in the CodeGen component, which may inadvertently discard high bits when a size value exceeds the range of the target type.
Users are advised to upgrade to NI gRPC Device Server version 2.18.0 or later. This vulnerability can also be addressed through the NI Update Service, which delivers security updates for NI software and drivers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-681 | Incorrect Conversion between Numeric Types | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni instrumentstudio | <= 2025 2026 q1 2026 q2 |
CPE
Remediation
| |
| ni ni grpc device server | < 2.18.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |