Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Geolocation Server HIGH 7.8
CVE-2023-36853

​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any locati…

Fix: after 2.4.2
Fix from $1,950 2023-07-19
Geolocation Server HIGH 7.8
CVE-2023-34394

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYS…

Fix: after 2.4.2
Fix from $1,950 2023-07-19
N8844a CRITICAL 9.8
CVE-2023-1967

Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.

Fix: after 2.1.7351
Fix from $2,300 2023-04-27
Hawkeye MEDIUM 6.1
CVE-2023-1860

A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. It has been declared as problematic. This vulnerability affects unknown code of the fil…

Mitigation only
Fix from $1,600 2023-04-05
N6854a Firmware CRITICAL 9.8
CVE-2023-1399

N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges i…

Fix: after 2.4.2
Fix from $2,300 2023-03-27
Sensor Management Server CRITICAL 9.8
CVE-2022-38129EPSS 19%

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management…

No fix yet
Fix from $2,300 2022-08-10
Sensor Management Server CRITICAL 9.8
CVE-2022-38130EPSS 54%

The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path…

Mitigation only
Fix from $2,300 2022-08-10
N6854a Firmware HIGH 7.5
CVE-2022-1661EPSS 16%

The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.

Fix: 2.4.0+
Fix from $1,950 2022-06-02
N6854a Firmware CRITICAL 9.8
CVE-2022-1660EPSS 17%

The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker…

Fix: 2.4.0+
Fix from $2,300 2022-06-02
Database Connector HIGH 8.8
CVE-2020-35121

An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript int…

Fix: 1.5.0+
Fix from $1,950 2020-12-15
Keysight Database Connector HIGH 7.5
CVE-2020-35122

An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for …

Fix: 1.5.0+
Fix from $1,950 2020-12-15