CVE-2026-49435
9.8 CRITICALPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw is a stack-based buffer overflow in Keysight IxChariot Endpoint, allowing unauthenticated remote attackers to execute arbitrary code with administrative privileges. This vulnerability is critical due to its high impact on system integrity and availability.
- Exploitability
- Exploitation is relatively straightforward given the unauthenticated nature and the ability to send a specially crafted packet. The attacker must have network access to the affected endpoint.
- Blast radius
- If exploited, the impact could be severe, as it allows for arbitrary code execution with administrative privileges, potentially leading to full system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of Keysight IxChariot Endpoint or apply the vendor's specific patch, as detailed in their advisory.
rcebuffer-overflowadmin-privilegenetworkunauthenticated
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-121
All references
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-216-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-49435
- https://www.keysight.com/us/en/about/quality-and-security/security/product-and-solution-cyber-security/security-advisory-archive/security-advisory--ixchariot-vulnerability.html
- https://www.keysight.com/us/en/lib/software-detail/computer-software/hawkeye.html
- https://www.keysight.com/us/en/lib/software-detail/computer-software/ixchariot.html
- https://www.keysight.com/us/en/lib/software-detail/instrument-firmware-software/ixprobe.html
- https://www.keysight.com/us/en/product/IXTP-CU3-T/copper-taps---ixtp-cu3-t.html
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2017-20242
- CRITICALCVE-2026-101038PoC
- CRITICALCVE-2026-76721
- CRITICALCVE-2026-76723
- CRITICALCVE-2026-101037PoC
- CRITICALCVE-2026-101039PoC
- CRITICALCVE-2026-101074PoC
- CRITICALCVE-2026-101081PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.