Executive brief
Keysight IxChariot Endpoint is a network testing and performance measurement tool. A stack-based buffer overflow vulnerability in versions before 9.5.102 allows an unauthenticated remote attacker to send a specially crafted packet that crashes the endpoint or executes arbitrary code, potentially compromising network testing infrastructure and operations.
Technical details
This is a stack-based buffer overflow vulnerability in Keysight IxChariot Endpoint. An unauthenticated remote attacker can exploit this by sending a specially crafted packet over the network to the affected endpoint. The vulnerability allows arbitrary code execution or denial of service (crash). The vulnerability affects versions before 9.5.102 and versions of IxChariot before 10.0.254. No authentication is required, and the attack is remotely exploitable via network access to the endpoint.
Affected products
- Keysight IxChariot Endpoint before 9.5.102
- Keysight IxChariot before 10.0.254
- Keysight Hawkeye before 6.0.7
- Keysight IxByPass before 3.13.0.69
- Keysight IxTap
- Keysight IxProbe
Timeline
- 2026-08-04: disclosed