CVE-2023-34394: Keysight N6845A Relative Path Traversal
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Keysight N6854A Geolocation serverto a version that resolves this vulnerability.Fixed in 2.4.3
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-34394.
What is the affected software?
The affected software is Keysight Geolocation Server v2.4.2 and prior.
What is the severity rating of CVE-2023-34394?
The severity rating of CVE-2023-34394 is high with a score of 7.8.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 434 and 23.
How can an attacker exploit CVE-2023-34394?
An attacker can exploit CVE-2023-34394 by uploading a specially crafted malicious file or deleting any file or directory with SYSTEM privileges.