External XML entity injection allows arbitrary download of files. The
score without least privilege principle violation is as calculated
below. In combination with other issues it may facilitate further
compromise of the device. Remediation in Version 6.8.0, release date:
01-Mar-25.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Mar 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Mar 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25. | |
Title | Keysight Ixia Vision Product Family Improper Restriction of XML External Entity Reference | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-03-05T15:17:23.659Z
Updated: 2025-03-06T21:57:07.875Z
Reserved: 2025-02-05T15:36:40.939Z
Link: CVE-2025-24521

Updated: 2025-03-06T21:56:52.982Z

Status : Received
Published: 2025-03-05T16:15:39.093
Modified: 2025-03-05T16:15:39.093
Link: CVE-2025-24521

No data.