CVE-2026-49435
Keysight · Hawkeye, IxChariot, IxTap, IxProbe, IxByPass
Multiple Keysight products contain a stack-based buffer overflow vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code with administrative privileges.
Executive summary
A critical stack-based buffer overflow across several Keysight products allows unauthenticated remote attackers to achieve administrative code execution, requiring immediate patching across the enterprise.
Vulnerability
This is a stack-based buffer overflow (CWE-121) that permits an unauthenticated attacker to send crafted packets to the affected software. Successful exploitation results in arbitrary code execution running with administrative privileges.
Business impact
This vulnerability carries a CVSS score of 9.8 and allows for full administrative control over the affected hardware and software. Such a compromise could lead to complete loss of confidentiality, integrity, and availability of network testing infrastructure, potentially exposing sensitive internal network traffic or configuration data to adversaries.
Remediation
Immediate Action: Update all affected software and firmware to the specified fixed versions: Hawkeye 6.0.7, IxChariot 10.0.254, IxTap 3.13.0, IxProbe 3.13.0, and IxByPass 3.13.0.69.
Proactive Monitoring: Watch for unusual administrative login activity or service behavior on all updated devices.
Compensating Controls: Isolate testing and monitoring segments from general-purpose network traffic to minimize the attack surface until all systems can be updated.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the broad impact across multiple Keysight product lines and the administrative level of access granted to attackers, this update should be prioritized across all affected environments. Failure to address this vulnerability poses a severe risk to the entire network monitoring and testing infrastructure.