Keysight Ixia Vision Product Family External XML Entity Injection Vulnerability Allowing Arbitrary File Download

Vulnerability

A vulnerability allowing external XML entity injection has been identified in the Keysight Ixia Vision Product Family, specifically in version 6.3.1. This vulnerability allows for the arbitrary download of files, and although it requires a privileged account for exploitation, it could lead to further compromise of the device when combined with other issues. The vulnerability arises from improper restriction of XML external entity references, which could be exploited to inject malicious XML that the application processes, potentially leading to unauthorized file access or manipulation.

Impact

Exploitation of this vulnerability could allow an attacker to download arbitrary files from the affected device, and in combination with other vulnerabilities, could facilitate further compromise of the device.

Remediation

Keysight recommends that all users upgrade to the latest version of the software as soon as possible. For more information about the Ixia Vision Product Family, visit the Ixia product support page. Questions can be directed to Keysight.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.