The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-24946 The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.
Fixes

Solution

Keysight recommends users update N6854A and N6841A RF to v2.4.0 or later. Keysight also recommends users take the following actions to help reduce risk: Block incoming connection on TCP port number defined by environment variable KEYSIGHT_SMS_PORT (default: 8080)


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:17:41.641Z

Reserved: 2022-05-10T00:00:00.000Z

Link: CVE-2022-1660

cve-icon Vulnrichment

Updated: 2024-08-03T00:10:03.803Z

cve-icon NVD

Status : Modified

Published: 2022-06-02T14:15:32.993

Modified: 2024-11-21T06:41:11.947

Link: CVE-2022-1660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.