Записи Keysight
11 опубликованных записей вендора keysight.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-502 Deserialization of Untrusted Data3
- CWE-23 Relative Path Traversal2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-749 Exposed Dangerous Method or Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2022-38130Proof of concept | The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS.keysight · sensor management server · CWE-89 | Критическая9,8 | — | 54,1 % | 10 авг. 2022 г. |
45В плане | CVE-2022-38129Эксплойта нет | A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Mkeysight · sensor management server · CWE-22 | Критическая9,8 | — | 18,9 % | 10 авг. 2022 г. |
44В плане | CVE-2022-1660Эксплойта нет | Keysight N6854A Geolocation server and N6841A RF Sensor softwarekeysight · n6854a firmware · CWE-502 | Критическая9,8 | — | 16,8 % | 2 июн. 2022 г. |
39Наблюдать | CVE-2023-1967Эксплойта нет | Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.keysight · n8844a · CWE-502 | Критическая9,8 | — | 0,8 % | 27 апр. 2023 г. |
39Наблюдать | CVE-2023-1399Эксплойта нет | N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate prkeysight · n6854a firmware · CWE-502 | Критическая9,8 | — | 0,8 % | 27 мар. 2023 г. |
35Наблюдать | CVE-2022-1661Эксплойта нет | Keysight N6854A Geolocation server and N6841A RF Sensor softwarekeysight · n6854a firmware · CWE-23 | Высокая7,5 | — | 15,9 % | 2 июн. 2022 г. |
35Наблюдать | CVE-2020-35121Эксплойта нет | An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.keysight · database connector | Высокая8,8 | — | 1,0 % | 15 дек. 2020 г. |
31Наблюдать | CVE-2023-34394Эксплойта нет | Keysight N6845A Relative Path Traversalkeysight · geolocation server · CWE-23 | Высокая7,8 | — | 0,2 % | 19 июл. 2023 г. |
31Наблюдать | CVE-2023-36853Эксплойта нет | Keysight Geolocation Server Exposed Dangerous Method or Functionkeysight · geolocation server · CWE-749 | Высокая7,8 | — | 0,2 % | 19 июл. 2023 г. |
30Наблюдать | CVE-2020-35122Эксплойта нет | An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.keysight · keysight database connector · CWE-89 | Высокая7,5 | — | 0,8 % | 15 дек. 2020 г. |
24Наблюдать | CVE-2023-1860Эксплойта нет | Keysight IXIA Hawkeye licenses cross site scriptingkeysight · hawkeye · CWE-79 | Средняя6,1 | — | 0,4 % | 5 апр. 2023 г. |
- CVE-2022-3813055В плане
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS.
КритическаяCVSS 9,8Proof of conceptEPSS 54 %keysight · sensor management server10 авг. 2022 г.
- CVE-2022-3812945В плане
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor M
КритическаяCVSS 9,8Эксплойта нетEPSS 19 %keysight · sensor management server10 авг. 2022 г.
- CVE-2022-166044В плане
Keysight N6854A Geolocation server and N6841A RF Sensor software
КритическаяCVSS 9,8Эксплойта нетEPSS 17 %keysight · n6854a firmware2 июн. 2022 г.
- CVE-2023-196739Наблюдать
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %keysight · n8844a27 апр. 2023 г.
- CVE-2023-139939Наблюдать
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate pr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %keysight · n6854a firmware27 мар. 2023 г.
- CVE-2022-166135Наблюдать
Keysight N6854A Geolocation server and N6841A RF Sensor software
ВысокаяCVSS 7,5Эксплойта нетEPSS 16 %keysight · n6854a firmware2 июн. 2022 г.
- CVE-2020-3512135Наблюдать
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %keysight · database connector15 дек. 2020 г.
- CVE-2023-3439431Наблюдать
Keysight N6845A Relative Path Traversal
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %keysight · geolocation server19 июл. 2023 г.
- CVE-2023-3685331Наблюдать
Keysight Geolocation Server Exposed Dangerous Method or Function
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %keysight · geolocation server19 июл. 2023 г.
- CVE-2020-3512230Наблюдать
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %keysight · keysight database connector15 дек. 2020 г.
- CVE-2023-186024Наблюдать
Keysight IXIA Hawkeye licenses cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %keysight · hawkeye5 апр. 2023 г.