Description
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
Published: 2026-08-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack‑based buffer overflow that exists in the packet parsing logic of Keysight's IxChariot Endpoint and related products. An unauthenticated attacker can send a single crafted packet that overflows the stack and allows execution of arbitrary code with administrative privileges. This results in full compromise of the device or software, enabling the attacker to read, modify, or delete any data and to disrupt network operations.

Affected Systems

The flaw affects all Keysight IxChariot Endpoint related tools, including IxChariot, Hawkeye, IxByPass, IxProbe and IxTap. No specific firmware or software version numbers are listed, so any build that contains the affected packet handling module is potentially vulnerable.

Risk and Exploitability

The CVSS score is 9.3, indicating a critical severity. Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk; the vulnerability is exploitable from the network by an unauthenticated user who can reach the affected service. Attack vectors likely involve a network packet that targets the product’s input interface. Because the flaw permits arbitrary code execution with administrative rights, the impact is total control over the affected system, exposing all data stored or processed by the product.

Generated by OpenCVE AI on August 4, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Keysight security update that fixes the stack‑based buffer overflow for all affected products (IxChariot, Hawkeye, IxByPass, IxProbe, and IxTap).
  • Configure firewall or ACL rules to block or tightly restrict unauthenticated traffic to the product‑specific interfaces until the update is available.
  • Run a vulnerability scan or penetration test to verify that the buffer‑overflow endpoint is no longer exposed after applying the update.

Generated by OpenCVE AI on August 4, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
Title Keysight IxChariot-related products stack-based buffer overflow
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-08-04T18:59:37.866Z

Reserved: 2026-05-29T21:56:48.486Z

Link: CVE-2026-49435

cve-icon Vulnrichment

Updated: 2026-08-04T18:59:34.740Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:30:05Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow