CVE-2022-1660: Keysight N6854A Geolocation server and N6841A RF Sensor software
Published May 31, 2022
·Updated
The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.
Affected Software
5 affected components
Keysight Technologies, Inc. Keysight N6854A and N6841A RF: Version 2.3.0 and earlier
keysight N6854a Firmware<2.4.0
keysight N6854A
keysight N6841a Rf Firmware<2.4.0
keysight N6841A RF
Remediation
Information
Keysight recommends users update N6854A and N6841A RF to v2.4.0 or later.
Keysight also recommends users take the following actions to help reduce risk:
Block incoming connection on TCP port number defined by environment variable KEYSIGHT_SMS_PORT (default: 8080)
Event History
May 31, 2022
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1660?
CVE-2022-1660 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2022-1660?
To mitigate CVE-2022-1660, upgrade to version 2.4.0 or later of the Keysight N6854A and N6841A RF products.
3
What products are affected by CVE-2022-1660?
The affected products include Keysight N6854A and N6841A RF versions 2.3.0 and earlier.
4
What type of vulnerability is CVE-2022-1660?
CVE-2022-1660 is a vulnerability related to the deserialization of untrusted data without authentication.
5
Can CVE-2022-1660 be exploited remotely?
Yes, CVE-2022-1660 can be exploited remotely, allowing attackers to execute arbitrary code.