CVE-2025-24494: Keysight Ixia Vision Product Family Path Traversal
Path traversal may allow remote code execution using privileged account (requires device admin account, cannot be performed by a regular user). In combination with the 'Upload' functionality this could be used to execute an arbitrary script or possibly an uploaded binary. Remediation in Version 6.7.0, release date: 20-Oct-24.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24494?
CVE-2025-24494 is considered a high-severity vulnerability due to its potential for remote code execution using a privileged account.
How do I fix CVE-2025-24494?
To remediate CVE-2025-24494, upgrade the affected Keysight Ixia Vision Product Family software to version 6.7.0 or later.
Who is affected by CVE-2025-24494?
CVE-2025-24494 affects users of the Keysight Ixia Vision Product Family, specifically versions up to 6.7.0.
Can a regular user exploit CVE-2025-24494?
No, CVE-2025-24494 can only be exploited by users with a device admin account.
What type of attack can CVE-2025-24494 facilitate?
CVE-2025-24494 can facilitate a path traversal attack that may allow for arbitrary script execution or binary uploads.