Junglewise Threat Intelligence

CVE-2023-4570: PYSEC-2026-1695 - NI MeasurementLink Python Services Improper Access Restriction vulnerability

CVE-2023-4570 · Severity: low · CVSS 3.1 · Published 2026-07-07

Vendors: PyPI.

Executive brief

NI MeasurementLink Python Services are components used to develop measurement and automation plug-ins. The vulnerability allows an attacker on an adjacent network to access services that were designed to be reachable only locally, potentially exposing sensitive measurement data or enabling remote command execution. This affects all Python measurement plug-ins using the ni-measurementlink-service package up to version 1.1.0.

Technical details

This is an improper access restriction vulnerability (CWE-420) in the ni-measurementlink-service Python package. The root cause is inadequate network isolation: localhost services are exposed in a way that allows adjacent network attackers to reach them without authentication or user interaction. The attack vector is adjacent network access with no privilege requirements. An attacker can gain high-impact access including confidentiality compromise (read sensitive data), integrity compromise (modify data or behavior), and availability compromise (disrupt service). Patches are available in versions 1.1.1 and 1.2.0 or later.

Affected products

  • National Instruments MeasurementLink Service <1.1.1, >=1.2.0-dev0, <1.2.0

Timeline

  • 2023-10-05: disclosed

References