PT-2021-7266 · Keysight · Keysight N6841A Rf Sensor+1

Rgod

·

Published

2021-12-30

·

Updated

2023-06-27

·

CVE-2022-1661

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keysight N6841A RF Sensor versions (affected versions not specified) Keysight N6854A Geo Location Server versions (affected versions not specified)
Description The issue is related to directory traversal errors in the UserFirmwareRequestHandler class implementation of the Keysight N6841A RF Sensor and Keysight N6854A Geo Location Server firmware. This may allow a remote attacker to obtain unauthorized access to protected information. The vulnerability can be exploited to disclose arbitrary operating system files.
Recommendations For Keysight N6841A RF Sensor, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Keysight N6854A Geo Location Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-04689
CVE-2022-1661
ZDI-22-805

Affected Products

Keysight N6841A Rf Sensor
Keysight N6854A Geo Location Server