CVE-2025-24521
Keysight Ixia Vision Product Family Improper Restriction of XML External Entity Reference
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.9EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
05 mar 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
External XML entity injection allows arbitrary download of files. The
score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Keysight · Ixia Vision Product Family¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →