CVE-2026-49435
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Keysight | Hawkeye | 0 < 6.0.7 | affected |
| Keysight | Hawkeye | 6.0.7 | unaffected |
| Keysight | IxChariot | 10.0.254 | unaffected |
| Keysight | IxChariot | 0 < 10.0.254 | affected |
| Keysight | IxTap | 0 < 3.13.0 | affected |
| Keysight | IxTap | 3.13.0 | unaffected |
| Keysight | IxProbe | 0 < 3.13.0 | affected |
| Keysight | IxProbe | 3.13.0 | unaffected |
| Keysight | IxByPass | 0 < 3.13.0.69 | affected |
| Keysight | IxByPass | 3.13.0.69 | unaffected |
Weaknesses
- CWE-121: CWE-121 Stack-based Buffer Overflow
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.keysight.com/us/en/lib/software-detail/computer-software/hawkeye.html
- https://www.keysight.com/us/en/about/quality-and-security/security/product-and-solution-cyber-security/security-advisory-archive/security-advisory–ixchariot-vulnerability.html
- https://www.keysight.com/us/en/lib/software-detail/computer-software/ixchariot.html
- https://www.keysight.com/us/en/lib/software-detail/instrument-firmware-software/ixprobe.html
- https://www.keysight.com/us/en/product/IXTP-CU3-T/copper-taps—ixtp-cu3-t.html
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-49435
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.