CVE-2025-24521
Keysight Ixia Vision Product Family Improper Restriction of XML External Entity Reference
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
External XML entity injection allows arbitrary download of files. The
score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Keysight · Ixia Vision Product FamilyWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →