Impact
This vulnerability is a stack‑based buffer overflow that exists in the packet parsing logic of Keysight's IxChariot Endpoint and related products. An unauthenticated attacker can send a single crafted packet that overflows the stack and allows execution of arbitrary code with administrative privileges. This results in full compromise of the device or software, enabling the attacker to read, modify, or delete any data and to disrupt network operations.
Affected Systems
The flaw affects all Keysight IxChariot Endpoint related tools, including IxChariot, Hawkeye, IxByPass, IxProbe and IxTap. No specific firmware or software version numbers are listed, so any build that contains the affected packet handling module is potentially vulnerable.
Risk and Exploitability
The CVSS score is 9.3, indicating a critical severity. Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk; the vulnerability is exploitable from the network by an unauthenticated user who can reach the affected service. Attack vectors likely involve a network packet that targets the product’s input interface. Because the flaw permits arbitrary code execution with administrative rights, the impact is total control over the affected system, exposing all data stored or processed by the product.
OpenCVE Enrichment