Impact
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow that can be triggered by an unauthenticated remote attacker sending a specially crafted packet. This flaw can crash the endpoint or lead to arbitrary code execution, granting the attacker full control over the affected system.
Affected Systems
The vulnerability affects Keysight IxChariot Endpoint deployments running any version earlier than 9.5.102. Any version older than this is susceptible.
Risk and Exploitability
This flaw has a high severity CVSS score of 9.3. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, indicating it may not yet be actively exploited on a large scale. However, the attack requires only unauthenticated network access and can be performed remotely by crafting a malicious packet, meaning attackers could potentially gain arbitrary execution on the endpoint if the system is exposed to untrusted networks.
OpenCVE Enrichment