CVE-2017-20242
Keysight · IxChariot
Keysight IxChariot Endpoint contains a stack-based buffer overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code or crash the system via crafted network packets.
Executive summary
A critical stack-based buffer overflow in Keysight IxChariot enables unauthenticated remote code execution, creating a high-risk security exposure for network infrastructure.
Vulnerability
The vulnerability is a stack-based buffer overflow (CWE-121) occurring during the handling of network packets. An unauthenticated remote attacker can send malicious packets to the endpoint to trigger the overflow and potentially execute arbitrary code with the privileges of the service.
Business impact
The ability for an unauthenticated attacker to execute code remotely presents a significant threat to organizational security. With a CVSS score of 9.8, this vulnerability could be leveraged to gain persistence within a network, facilitate lateral movement, or cause catastrophic service failure, leading to major business disruption.
Remediation
Immediate Action: Upgrade Keysight IxChariot installations to version 9.5.102 or higher to remediate the buffer overflow flaw.
Proactive Monitoring: Monitor system and application logs for unexpected crashes or service restarts that may indicate attempted exploitation.
Compensating Controls: Restrict network access to the affected IxChariot services using firewalls or Access Control Lists to ensure only trusted segments can reach the application.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations must treat this vulnerability as high priority and apply the vendor-supplied update immediately. Failure to patch these endpoints leaves the network susceptible to remote compromise by unauthenticated actors.