CVE-2022-38129

CRITICAL

Keysight Sensor Mgmt Server - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

Scores

CVSS v3 9.8
EPSS 0.0317
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-24
Status published
Products (1)
keysight/sensor_management_server 2.4.0
Published Aug 10, 2022
Tracked Since Feb 18, 2026