Keysight's vulnerability profile centers on a narrow range of network-test and measurement instruments, including RF and geolocation appliances and their firmware components, which operate in specialized engineering and telecom deployment contexts. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through application-layer weakness classes including unsafe deserialization, path traversal, SQL injection, and exposed dangerous methods that reflect inadequate input validation and access control in command-line and API interfaces. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keysight over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38130CRITICAL The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as | Aug 10, 2022 | 9.8 | 72 | NO | YES |
CVE-2022-38129CRITICAL A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an u | Aug 10, 2022 | 9.8 | 40 | NO | NO |
CVE-2022-1661HIGH The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. | Jun 2, 2022 | 7.5 | 32 | NO | NO |
CVE-2022-1660CRITICAL The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-1399CRITICAL
N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s defaul | Mar 27, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-1967CRITICAL Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. | Apr 27, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-35121HIGH An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that w | Dec 15, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-35122HIGH An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connecti | Dec 15, 2020 | 7.5 | 23 | NO | NO |
CVE-2023-36853HIGH
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abu | Jul 19, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-34394HIGH
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an | Jul 19, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keysight.
Media articles that mention a CVE ID that affects a product developed by Keysight — matched by CVE ID, not by vendor name.