NI has released software patches for a security vulnerability that affects the NI Linux Real-Time operating system for the targets listed in the following table. Please review the installation instructions for each product family below. If you are using devices from two or more of the affected product families, complete the installation instructions for each applicable product family to ensure that all affected targets are patched.
Software Family | Target |
CompactRIO | cRIO-9030 |
cRIO-9031 | |
cRIO-9033 | |
cRIO-9034 | |
cRIO-9038 | |
cRIO-9066 | |
cRIO-9067 | |
cRIO-9068 | |
NI 9149 | |
sbRIO-9651 | |
myRIO-1900 | |
myRIO-1950 | |
NI roboRIO | |
Compact Vision System | CVS-1458RT |
CVS-1459RT | |
CompactDAQ | cDAQ-9132 |
cDAQ-9134 | |
NI strongly recommends that you install this patch to fix this vulnerability if you have or intend to use one of the devices listed above.
Complete the following steps to ensure that any current or future devices have this security update included.
You must complete each of the following steps to ensure that any current or future devices have this security update included.
Ensure that you have patched all development systems.
You must complete each of the following steps to ensure that any current or future devices have this security update included.
A family of security vulnerabilities, commonly known as "Shellshock," affects Linux distributions that use GNU Bash, including the NI Linux Real-Time operating system. These vulnerabilities allow remote attackers to execute arbitrary code and gain unauthorized access to the system. Exploitation of this vulnerability allows unauthorized disclosure of information, unauthorized modification, and disruption of service. The National Vulnerability Database (NVD), the U.S. government’s repository of standards based vulnerability management data, reported a Common Vulnerability Scoring System (CVSS) base score of 10.0 which is the highest possible severity score.
All NI controllers that run the NI Linux Real-Time operating system are affected by Shellshock. This security update addresses the following reported vulnerabilities:
CVE-2014-6271
CVE-2014-6277
CVE-2014-6278
CVE-2014-7169
CVE-2014-7186
CVE-2014-7187
Follow the steps listed above to install the appropriate software patch.