N6854a Firmware
by Keysight
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1660 | Cri | 0.65 | 9.8 | 0.16 | Jun 2, 2022 | The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2023-1399 | Hig | 0.51 | 7.8 | 0.01 | Mar 27, 2023 | N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution. | ||
| CVE-2022-1661 | Hig | 0.50 | 7.5 | 0.15 | Jun 2, 2022 | The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. |
- risk 0.65cvss 9.8epss 0.16
The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.
- risk 0.50cvss 7.5epss 0.15
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.