VYPR
Medium severity6.1NVD Advisory· Published Apr 21, 2022· Updated Jun 17, 2026

CVE-2022-27237

CVE-2022-27237

Description

There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

18
  • Ni/FlexLogger4 versions
    cpe:2.3:a:ni:flexlogger:2021:r2:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:ni:flexlogger:2021:r2:*:*:*:*:*:*
    • cpe:2.3:a:ni:flexlogger:2021:r3:*:*:*:*:*:*
    • cpe:2.3:a:ni:flexlogger:2021:r4:*:*:*:*:*:*
    • (no CPE)range: >=2022 Q2
  • cpe:2.3:a:ni:g_web_development_software:2021:*:*:*:-:*:*:*+ 2 more
    • cpe:2.3:a:ni:g_web_development_software:2021:*:*:*:-:*:*:*
    • cpe:2.3:a:ni:g_web_development_software:2021:*:*:*:community:*:*:*
    • (no CPE)range: >=2022 R1
  • Ni/Labview3 versions
    cpe:2.3:a:ni:labview:2021:-:*:*:-:*:*:*+ 2 more
    • cpe:2.3:a:ni:labview:2021:-:*:*:-:*:*:*
    • cpe:2.3:a:ni:labview:2021:-:*:*:community:*:*:*
    • (no CPE)range: >=2021 SP1
  • cpe:2.3:a:ni:static_test_software_suite:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ni:static_test_software_suite:*:*:*:*:*:*:*:*range: <1.2
    • (no CPE)range: >=1.2
  • Ni/Systemlink3 versions
    cpe:2.3:a:ni:systemlink:2020:r4:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ni:systemlink:2020:r4:*:*:*:*:*:*
    • cpe:2.3:a:ni:systemlink:2022:r1:*:*:*:*:*:*
    • cpe:2.3:a:ni:systemlink:2022:r2:*:*:*:*:*:*
  • NI/NI Web Serverdescription
  • Ni/NI Web Serverllm-create
  • Range: >=2021 R3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.