CVE-2023-1399

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
27/03/2023
Last modified:
07/11/2023

Description

<br /> N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:keysight:n6854a_firmware:*:*:*:*:*:*:*:* 2.4.2 (including)
cpe:2.3:h:keysight:n6854a:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools