Medium severity6.1NVD Advisory· Published Apr 21, 2022· Updated Jun 17, 2026
CVE-2022-27237
CVE-2022-27237
Description
There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:a:ni:flexlogger:2021:r2:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:ni:flexlogger:2021:r2:*:*:*:*:*:*
- cpe:2.3:a:ni:flexlogger:2021:r3:*:*:*:*:*:*
- cpe:2.3:a:ni:flexlogger:2021:r4:*:*:*:*:*:*
- (no CPE)range: >=2022 Q2
cpe:2.3:a:ni:g_web_development_software:2021:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:ni:g_web_development_software:2021:*:*:*:-:*:*:*
- cpe:2.3:a:ni:g_web_development_software:2021:*:*:*:community:*:*:*
- (no CPE)range: >=2022 R1
cpe:2.3:a:ni:static_test_software_suite:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ni:static_test_software_suite:*:*:*:*:*:*:*:*range: <1.2
- (no CPE)range: >=1.2
cpe:2.3:a:ni:systemlink:2020:r4:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ni:systemlink:2020:r4:*:*:*:*:*:*
- cpe:2.3:a:ni:systemlink:2022:r1:*:*:*:*:*:*
- cpe:2.3:a:ni:systemlink:2022:r2:*:*:*:*:*:*
- NI/NI Web Serverdescription
- Range: >=2021 R3
Patches
Vulnerability mechanics
References
1- www.ni.com/en-us/support/documentation/supplemental/22/cross-site-scripting-vulnerability--in-ni-web-server-component.htmlnvdMitigationPatchVendor Advisory
News mentions
0No linked articles in our index yet.