CVE-2026-49435 PUBLISHED

Keysight IxChariot-related products stack-based buffer overflow

Assigner: cisa-cg
Reserved: 29.05.2026 Published: 04.08.2026 Updated: 04.08.2026

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Keysight
Product Hawkeye
Versions Default: unknown
  • affected from 0 to 6.0.7 (excl.)
  • Version 6.0.7 is unaffected
Vendor Keysight
Product IxChariot
Versions Default: unknown
  • Version 10.0.254 is unaffected
  • affected from 0 to 10.0.254 (excl.)
Vendor Keysight
Product IxTap
Versions Default: unknown
  • affected from 0 to 3.13.0 (excl.)
  • Version 3.13.0 is unaffected
Vendor Keysight
Product IxProbe
Versions Default: unknown
  • affected from 0 to 3.13.0 (excl.)
  • Version 3.13.0 is unaffected
Vendor Keysight
Product IxByPass
Versions Default: unknown
  • affected from 0 to 3.13.0.69 (excl.)
  • Version 3.13.0.69 is unaffected

Credits

  • Sébastien Charbonnier, ANSSI

References

Problem Types

  • CWE-121 Stack-based Buffer Overflow CWE