PT-2021-7266 · Keysight · Keysight N6841A Rf Sensor+1
Rgod
·
Published
2021-12-30
·
Updated
2023-06-27
·
CVE-2022-1661
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keysight N6841A RF Sensor versions (affected versions not specified)
Keysight N6854A Geo Location Server versions (affected versions not specified)
Description
The issue is related to directory traversal errors in the UserFirmwareRequestHandler class implementation of the Keysight N6841A RF Sensor and Keysight N6854A Geo Location Server firmware. This may allow a remote attacker to obtain unauthorized access to protected information. The vulnerability can be exploited to disclose arbitrary operating system files.
Recommendations
For Keysight N6841A RF Sensor, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Keysight N6854A Geo Location Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keysight N6841A Rf Sensor
Keysight N6854A Geo Location Server