Vulnerabilities > Keysight
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-19 | CVE-2023-34394 | Unrestricted Upload of File with Dangerous Type vulnerability in Keysight Geolocation Server In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition. | 7.8 |
2023-07-19 | CVE-2023-36853 | Uncontrolled Search Path Element vulnerability in Keysight Geolocation Server ?In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. | 7.8 |
2023-04-27 | CVE-2023-1967 | Deserialization of Untrusted Data vulnerability in Keysight N8844A 2.1.7351 Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. | 9.8 |
2023-04-05 | CVE-2023-1860 | Cross-site Scripting vulnerability in Keysight Hawkeye 3.3.16.28 A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. | 6.1 |
2023-03-27 | CVE-2023-1399 | Deserialization of Untrusted Data vulnerability in Keysight N6854A Firmware 2.3.0/2.4.0/2.4.2 N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution. | 9.8 |
2022-06-02 | CVE-2022-1660 | Deserialization of Untrusted Data vulnerability in Keysight N6841A RF Firmware and N6854A Firmware The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code. | 10.0 |
2022-06-02 | CVE-2022-1661 | Path Traversal vulnerability in Keysight N6841A RF Firmware and N6854A Firmware The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. | 7.5 |
2020-12-15 | CVE-2020-35122 | SQL Injection vulnerability in Keysight Database Connector An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. | 4.0 |
2020-12-15 | CVE-2020-35121 | Code Injection vulnerability in Keysight Database Connector An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. | 6.8 |