Keysight records
11 published records for vendor keysight.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data3
- CWE-23 Relative Path Traversal2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-749 Exposed Dangerous Method or Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2022-38130Proof of concept | The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS.keysight · sensor management server · CWE-89 | Critical9.8 | — | 54.1% | Aug 10, 2022 |
45Plan | CVE-2022-38129No exploit | A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Mkeysight · sensor management server · CWE-22 | Critical9.8 | — | 18.9% | Aug 10, 2022 |
44Plan | CVE-2022-1660No exploit | Keysight N6854A Geolocation server and N6841A RF Sensor softwarekeysight · n6854a firmware · CWE-502 | Critical9.8 | — | 16.8% | Jun 2, 2022 |
39Monitor | CVE-2023-1967No exploit | Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.keysight · n8844a · CWE-502 | Critical9.8 | — | 0.8% | Apr 27, 2023 |
39Monitor | CVE-2023-1399No exploit | N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate prkeysight · n6854a firmware · CWE-502 | Critical9.8 | — | 0.8% | Mar 27, 2023 |
35Monitor | CVE-2022-1661No exploit | Keysight N6854A Geolocation server and N6841A RF Sensor softwarekeysight · n6854a firmware · CWE-23 | High7.5 | — | 15.9% | Jun 2, 2022 |
35Monitor | CVE-2020-35121No exploit | An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.keysight · database connector | High8.8 | — | 1.0% | Dec 15, 2020 |
31Monitor | CVE-2023-34394No exploit | Keysight N6845A Relative Path Traversalkeysight · geolocation server · CWE-23 | High7.8 | — | 0.2% | Jul 19, 2023 |
31Monitor | CVE-2023-36853No exploit | Keysight Geolocation Server Exposed Dangerous Method or Functionkeysight · geolocation server · CWE-749 | High7.8 | — | 0.2% | Jul 19, 2023 |
30Monitor | CVE-2020-35122No exploit | An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.keysight · keysight database connector · CWE-89 | High7.5 | — | 0.8% | Dec 15, 2020 |
24Monitor | CVE-2023-1860No exploit | Keysight IXIA Hawkeye licenses cross site scriptingkeysight · hawkeye · CWE-79 | Medium6.1 | — | 0.4% | Apr 5, 2023 |
- CVE-2022-3813055Plan
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS.
CriticalCVSS 9.8Proof of conceptEPSS 54%keysight · sensor management serverAug 10, 2022
- CVE-2022-3812945Plan
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor M
CriticalCVSS 9.8No exploitEPSS 19%keysight · sensor management serverAug 10, 2022
- CVE-2022-166044Plan
Keysight N6854A Geolocation server and N6841A RF Sensor software
CriticalCVSS 9.8No exploitEPSS 17%keysight · n6854a firmwareJun 2, 2022
- CVE-2023-196739Monitor
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.
CriticalCVSS 9.8No exploitEPSS 1%keysight · n8844aApr 27, 2023
- CVE-2023-139939Monitor
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate pr
CriticalCVSS 9.8No exploitEPSS 1%keysight · n6854a firmwareMar 27, 2023
- CVE-2022-166135Monitor
Keysight N6854A Geolocation server and N6841A RF Sensor software
HighCVSS 7.5No exploitEPSS 16%keysight · n6854a firmwareJun 2, 2022
- CVE-2020-3512135Monitor
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.
HighCVSS 8.8No exploitEPSS 1%keysight · database connectorDec 15, 2020
- CVE-2023-3439431Monitor
Keysight N6845A Relative Path Traversal
HighCVSS 7.8No exploitEPSS 0%keysight · geolocation serverJul 19, 2023
- CVE-2023-3685331Monitor
Keysight Geolocation Server Exposed Dangerous Method or Function
HighCVSS 7.8No exploitEPSS 0%keysight · geolocation serverJul 19, 2023
- CVE-2020-3512230Monitor
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.
HighCVSS 7.5No exploitEPSS 1%keysight · keysight database connectorDec 15, 2020
- CVE-2023-186024Monitor
Keysight IXIA Hawkeye licenses cross site scripting
MediumCVSS 6.1No exploitEPSS 0%keysight · hawkeyeApr 5, 2023