Impact
A stack-based buffer overflow exists in Keysight IxChariot Endpoint prior to version 9.5.102. An attacker who can send a specially crafted packet can trigger the overflow, which may cause the endpoint to crash or potentially allow the execution of arbitrary code. The flaw therefore threatens confidentiality, integrity, and availability by giving an attacker the ability to take full control of the device.
Affected Systems
All Keysight IxChariot Endpoint installations running a firmware version earlier than 9.5.102 are vulnerable. Any instance that has not applied the documented security update remains at risk.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity flaw that is exploitable remotely without authentication. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be over the network, where an unauthenticated attacker can send malicious packets to a reachable endpoint port, leading to crash or code execution.
OpenCVE Enrichment