Description
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
Published: 2026-08-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow that can be triggered by an unauthenticated remote attacker sending a specially crafted packet. This flaw can crash the endpoint or lead to arbitrary code execution, granting the attacker full control over the affected system.

Affected Systems

The vulnerability affects Keysight IxChariot Endpoint deployments running any version earlier than 9.5.102. Any version older than this is susceptible.

Risk and Exploitability

This flaw has a high severity CVSS score of 9.3. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, indicating it may not yet be actively exploited on a large scale. However, the attack requires only unauthenticated network access and can be performed remotely by crafting a malicious packet, meaning attackers could potentially gain arbitrary execution on the endpoint if the system is exposed to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the IxChariot Endpoint to version 9.5.102 or later, which contains the official fix for the buffer overflow.
  • If an immediate upgrade is not possible, restrict network access to the endpoint by applying firewall rules that block traffic from untrusted sources.
  • Apply any interim configuration changes recommended by Keysight, such as disabling unused services or reducing exposure to external network traffic, until the patch can be applied.
  • Continuously monitor for any new advisories from Keysight regarding the vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
Title Keysight IxChariot Endpoint heap-based buffer overflow
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-08-04T18:58:55.123Z

Reserved: 2026-05-29T21:50:59.765Z

Link: CVE-2017-20241

cve-icon Vulnrichment

Updated: 2026-08-04T18:58:52.557Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:30:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow