score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
Metrics
Affected Vendors & Products
Solution
Keysight recommends that all users upgrade to the latest version of software as soon as possible. https://support.ixiacom.com/support-overview/product-support/downloads-updates Remediation in Version 6.8.0, release date: 01-Mar-25. Older versions of this software may have this vulnerability; Keysight recommends that users discontinue the use of older software versions. For more information about the Ixia Vision Product Family, please visit Ixia product support https://support.ixiacom.com/ Further questions can be answered by contacting Keysight. https://www.keysight.com/us/en/contact.html
Workaround
No workaround given by the vendor.
Thu, 06 Mar 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Mar 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25. | |
Title | Keysight Ixia Vision Product Family Improper Restriction of XML External Entity Reference | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-03-06T21:57:07.875Z
Reserved: 2025-02-05T15:36:40.939Z
Link: CVE-2025-24521

Updated: 2025-03-06T21:56:52.982Z

Status : Received
Published: 2025-03-05T16:15:39.093
Modified: 2025-03-05T16:15:39.093
Link: CVE-2025-24521

No data.

No data.