Path traversal may allow remote code execution using privileged account
(requires device admin account, cannot be performed by a regular user).
In combination with the 'Upload' functionality this could be used to
execute an arbitrary script or possibly an uploaded binary. Remediation
in Version 6.7.0, release date: 20-Oct-24.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Mar 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Path traversal may allow remote code execution using privileged account (requires device admin account, cannot be performed by a regular user). In combination with the 'Upload' functionality this could be used to execute an arbitrary script or possibly an uploaded binary. Remediation in Version 6.7.0, release date: 20-Oct-24. | |
Title | Keysight Ixia Vision Product Family Path Traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-03-05T15:15:19.986Z
Updated: 2025-03-05T16:09:05.368Z
Reserved: 2025-02-05T15:36:40.967Z
Link: CVE-2025-24494

Updated: 2025-03-05T16:09:01.382Z

Status : Received
Published: 2025-03-05T16:15:38.937
Modified: 2025-03-05T16:15:38.937
Link: CVE-2025-24494

No data.