Executive brief
Keysight IxChariot Endpoint is a network performance testing tool used by IT teams to measure and optimize application and network performance. An unauthenticated attacker can send a specially crafted network packet to trigger a heap buffer overflow, potentially crashing the endpoint service or executing arbitrary code to compromise systems and network infrastructure.
Technical details
The vulnerability is a heap-based buffer overflow in Keysight IxChariot Endpoint and related products (Hawkeye, IxTap, IxByPass, and IxProbe). An unauthenticated remote attacker can send a specially crafted packet over the network to trigger the overflow without requiring authentication. Successful exploitation allows arbitrary code execution with the privileges of the endpoint service, potentially leading to full system compromise. The vulnerability affects IxChariot Endpoint versions before 9.5.102 and 10.0.254; patches are available in version 9.5.102 and later.
Affected products
- Keysight IxChariot Endpoint before 9.5.102 and before 10.0.254
- Keysight Hawkeye before 6.0.7
- Keysight IxByPass before 3.13.0.69
- Keysight IxTap <UNKNOWN>
- Keysight IxProbe <UNKNOWN>
Timeline
- 2026-08-04: disclosed: CISA advisory VA-26-216-01 published