CVE-2025-24521
Keysight Ixia Vision Product Family Improper Restriction of XML External Entity Reference
External XML entity injection allows arbitrary download of files. The
score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Keysight · Ixia Vision Product FamilyQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →