PT-2021-7260 · Keysight · Keysight N6854A Geo Location Server+1

Rgod

·

Published

2021-12-30

·

Updated

2022-06-09

·

CVE-2022-1660

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Keysight N6841A RF Sensor versions (affected versions not specified) Keysight N6854A Geo-Location Server versions (affected versions not specified)
Description The issue is related to the deserialization of untrusted data without prior authorization or authentication, which may allow a remote attacker to execute arbitrary code. This is due to a vulnerability in the implementation of the Spring Framework configuration in the microprogrammed software of the sensors for monitoring the Keysight N6841A RF spectrum and the microprogrammed software of the Keysight N6854A geo-location servers. The vulnerability is associated with the recovery in memory of an untrusted data structure.
Recommendations For Keysight N6841A RF Sensor, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Keysight N6854A Geo-Location Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04559
CVE-2022-1660
ZDI-22-804

Affected Products

Keysight N6841A Rf Sensor
Keysight N6854A Geo Location Server