KeysightCVEs & Vulnerabilities

11 CVEs affecting Keysight products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

n6854a firmware 3n6854a 3n6841a rf 2n6841a rf firmware 2sensor management server 2geolocation server 2keysight database connector 1hawkeye 1
CVE-2022-38130KEVCRITICALin the wild

The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored.

11 Apr 2026
9.8
CVSS
CVE-2023-36853HIGH

​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.

20 Jul 2023
7.8
CVSS
CVE-2023-34394HIGH

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.

20 Jul 2023
7.8
CVSS
CVE-2023-1967CRITICAL

Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.

28 Apr 2023
9.8
CVSS
CVE-2023-1860MEDIUM

A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. It has been declared as problematic. This vulnerability affects unknown code of the file /licenses. The manipulation of the argument view with the input teste"><script>alert(%27c4ng4c3ir0%27)</script> leads to cross site scripting. The attack can be initiated remotely. VDB-224998 is the identifier assigned to this vulnerability. NOTE: Vendor did not respond if and how they may handle this issue.

5 Apr 2023
6.1
CVSS
CVE-2023-1399CRITICAL

N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.

27 Mar 2023
9.8
CVSS
CVE-2022-38129CRITICAL

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

10 Aug 2022
9.8
CVSS
CVE-2022-1661HIGH

The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.

2 Jun 2022
7.5
CVSS
CVE-2022-1660CRITICAL

The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.

2 Jun 2022
9.8
CVSS
CVE-2020-35122HIGH

An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.

16 Dec 2020
7.5
CVSS
CVE-2020-35121HIGH

An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that would execute when a user viewed a page with that instance of the macro.

16 Dec 2020
8.8
CVSS
← PrevPage 1 / 1Next →