VDB
Sign up
HIGH8.8

PYSEC-2026-1695

NI MeasurementLink Python Services Improper Access Restriction vulnerability

Quick fix

PYSEC-2026-1695 — ni-measurementlink-service: upgrade to the fixed version with the command below.

pip install --upgrade 'ni-measurementlink-service>=1.1.1'

Details

### Impact An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the `ni-measurementlink-service` Python package and all previous versions.

### Patches Upgrade all Python measurement plug-ins to use `ni-measurementlink-service` version 1.1.1 or later.

### References Visit [ni.com/info](http://www.ni.com/info) and enter the info code `cve-2023-4570` for more information.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ni-measurementlink-service
Introduced in: 0Fixed in: 1.1.1
Fixpip install --upgrade 'ni-measurementlink-service>=1.1.1'

References