{"id":"CVE-2026-49435","published":"2026-08-04T19:16:51.810","lastModified":"2026-08-04T20:16:52.160","description":"Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-121"],"vendors":[],"products":[],"references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json","tags":[]},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49435","tags":[]},{"url":"https://www.keysight.com/us/en/about/quality-and-security/security/product-and-solution-cyber-security/security-advisory-archive/security-advisory--ixchariot-vulnerability.html","tags":[]},{"url":"https://www.keysight.com/us/en/lib/software-detail/computer-software/hawkeye.html","tags":[]},{"url":"https://www.keysight.com/us/en/lib/software-detail/computer-software/ixchariot.html","tags":[]},{"url":"https://www.keysight.com/us/en/lib/software-detail/instrument-firmware-software/ixprobe.html","tags":[]},{"url":"https://www.keysight.com/us/en/product/IXTP-CU3-T/copper-taps---ixtp-cu3-t.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a stack-based buffer overflow in Keysight IxChariot Endpoint, allowing unauthenticated remote attackers to execute arbitrary code with administrative privileges. This vulnerability is critical due to its high impact on system integrity and availability.","exploitability":"Exploitation is relatively straightforward given the unauthenticated nature and the ability to send a specially crafted packet. The attacker must have network access to the affected endpoint.","blast_radius":"If exploited, the impact could be severe, as it allows for arbitrary code execution with administrative privileges, potentially leading to full system compromise.","remediation":"Upgrade to the latest version of Keysight IxChariot Endpoint or apply the vendor's specific patch, as detailed in their advisory.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","buffer-overflow","admin-privilege","network","unauthenticated"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:02:00.193Z"}}