← back
CVE-2025-24525

Keysight Ixia Vision Product Family Use of Hard-coded Cryptographic Key

CVSS 8.7 HIGHEPSS 0.2%CWE-321
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1, released on September 23, 2025.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →