PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-10494 NI CVE debrief

An out-of-bounds read vulnerability exists in the HeapObjMapImpl function within National Instruments LabVIEW. This memory safety defect may allow an attacker to disclose sensitive information or achieve arbitrary code execution. The vulnerability affects multiple LabVIEW versions including 2024 (up to Q3 24.3f0), 2023, 2022, and end-of-life versions 2021 and below. National Instruments has released patched versions for supported releases.

Vendor
NI
Product
LabVIEW 2024
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-10
Original CVE updated
2024-12-10
Advisory published
2024-12-10
Advisory updated
2024-12-10

Who should care

Organizations using National Instruments LabVIEW for test, measurement, and control applications, particularly in industrial and research environments. System administrators maintaining LabVIEW deployments across engineering workstations and HMI systems. Security teams responsible for industrial control system asset protection.

Technical summary

The vulnerability resides in the HeapObjMapImpl function, where an out-of-bounds read condition exists. This type of memory safety vulnerability typically occurs when software reads data beyond the bounds of allocated memory buffers. Successful exploitation may result in information disclosure through memory content exposure, or arbitrary code execution if the read can be leveraged to influence program control flow. The CVSS 3.1 vector indicates local attack vector with low attack complexity, no privileges required, but user interaction required. The confidentiality, integrity, and availability impacts are all rated HIGH.

Defensive priority

high

Recommended defensive actions

  • Upgrade LabVIEW 2024 installations to Q3 Patch 2 or later via NI Package Manager
  • Upgrade LabVIEW 2023 installations to Q3 Patch 5 or later via NI Package Manager
  • Upgrade LabVIEW 2022 installations to Q3 Patch 4 or later via NI Package Manager
  • Replace LabVIEW 2021 and earlier end-of-life versions with supported releases
  • Apply defense-in-depth controls for systems where immediate patching is not feasible
  • Monitor CISA ICS advisories for additional guidance on industrial control system security

Evidence notes

CISA published advisory ICSA-24-345-04 on 2024-12-10 documenting this vulnerability in National Instruments LabVIEW. The advisory confirms the out-of-bounds read in HeapObjMapImpl with potential for information disclosure and code execution. CVSS 3.1 score of 7.8 (HIGH) assigned with vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-10494 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-10494

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-10494 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10494

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.