CVE-2025-24525: Keysight Ixia Vision Product Family Use of Hard-coded Cryptographic Key
Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1, released on September 23, 2025.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24525?
CVE-2025-24525 is considered a significant vulnerability due to the potential for attackers to intercept or decrypt sensitive information.
How do I fix CVE-2025-24525?
To fix CVE-2025-24525, users should replace the default TLS certificate that comes with Keysight Ixia Vision devices.
What versions of Keysight Ixia Vision are affected by CVE-2025-24525?
CVE-2025-24525 affects Keysight Ixia Vision versions up to and including 6.9.1 and specifically version 6.3.1.
What impact does CVE-2025-24525 have on user data?
CVE-2025-24525 may allow unauthorized interception or decryption of sensitive user data transmitted through the device.
Is there a workaround for CVE-2025-24525 if I cannot replace the TLS certificate immediately?
The best course of action is to replace the TLS certificate as soon as possible since there are no defined workarounds that mitigate the risks involved.