Junglewise Threat Intelligence

CVE-2017-20242: Keysight IxChariot Endpoint stack buffer overflow

CVE-2017-20242 · Severity: critical · CVSS 9.8 · Published 2026-08-04

Technologies: Keysight IxByPass, Keysight IxTap, Keysight IxChariot Endpoint, Keysight Hawkeye, Keysight IxProbe. Vendors: Keysight.

Executive brief

Keysight IxChariot Endpoint is a network testing and performance measurement tool. A stack-based buffer overflow vulnerability in versions before 9.5.102 allows an unauthenticated remote attacker to send a specially crafted packet that crashes the endpoint or executes arbitrary code, potentially compromising network testing infrastructure and operations.

Technical details

This is a stack-based buffer overflow vulnerability in Keysight IxChariot Endpoint. An unauthenticated remote attacker can exploit this by sending a specially crafted packet over the network to the affected endpoint. The vulnerability allows arbitrary code execution or denial of service (crash). The vulnerability affects versions before 9.5.102 and versions of IxChariot before 10.0.254. No authentication is required, and the attack is remotely exploitable via network access to the endpoint.

Affected products

  • Keysight IxChariot Endpoint before 9.5.102
  • Keysight IxChariot before 10.0.254
  • Keysight Hawkeye before 6.0.7
  • Keysight IxByPass before 3.13.0.69
  • Keysight IxTap
  • Keysight IxProbe

Timeline

  • 2026-08-04: disclosed

References

Related threats