CVE-2017-20242

Keysight · IxChariot

Keysight IxChariot Endpoint contains a stack-based buffer overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code or crash the system via crafted network packets.

Executive summary

A critical stack-based buffer overflow in Keysight IxChariot enables unauthenticated remote code execution, creating a high-risk security exposure for network infrastructure.

Vulnerability

The vulnerability is a stack-based buffer overflow (CWE-121) occurring during the handling of network packets. An unauthenticated remote attacker can send malicious packets to the endpoint to trigger the overflow and potentially execute arbitrary code with the privileges of the service.

Business impact

The ability for an unauthenticated attacker to execute code remotely presents a significant threat to organizational security. With a CVSS score of 9.8, this vulnerability could be leveraged to gain persistence within a network, facilitate lateral movement, or cause catastrophic service failure, leading to major business disruption.

Remediation

Immediate Action: Upgrade Keysight IxChariot installations to version 9.5.102 or higher to remediate the buffer overflow flaw.

Proactive Monitoring: Monitor system and application logs for unexpected crashes or service restarts that may indicate attempted exploitation.

Compensating Controls: Restrict network access to the affected IxChariot services using firewalls or Access Control Lists to ensure only trusted segments can reach the application.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations must treat this vulnerability as high priority and apply the vendor-supplied update immediately. Failure to patch these endpoints leaves the network susceptible to remote compromise by unauthenticated actors.