N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23655 N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.
Fixes

Solution

Keysight recommends upgrading the N6854A Geolocation server to version 2.4.3 https://www.keysight.com/us/en/lib/software-detail/computer-software/n6854a-geolocation-server-and-n6841a-rf-sensor-software-sw319.html .


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:38:51.200Z

Reserved: 2023-03-14T14:44:01.960Z

Link: CVE-2023-1399

cve-icon Vulnrichment

Updated: 2024-08-02T05:49:11.558Z

cve-icon NVD

Status : Modified

Published: 2023-03-27T16:15:09.890

Modified: 2024-11-21T07:39:06.790

Link: CVE-2023-1399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.