ZDI-CAN-19603: ZDI-23-490: KeySight N8844A Data Analytics Web Service Unmarshal Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published May 1, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of KeySight N8844A Data Analytics Web Service. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
keysight N8844A Data Analytics Web Service
Event History
May 1, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19603?
The severity of ZDI-CAN-19603 is critical due to the potential for remote code execution without authentication.
2
How do I fix ZDI-CAN-19603?
To fix ZDI-CAN-19603, update the KeySight N8844A Data Analytics Web Service to the latest version provided by the vendor.
3
What systems are affected by ZDI-CAN-19603?
ZDI-CAN-19603 affects installations of KeySight N8844A Data Analytics Web Service.
4
Can ZDI-CAN-19603 be exploited without authentication?
Yes, ZDI-CAN-19603 can be exploited without any authentication, making it particularly dangerous.
5
What type of attack does ZDI-CAN-19603 facilitate?
ZDI-CAN-19603 facilitates remote code execution attacks, allowing attackers to run arbitrary code on the server.