CVE-2025-24521

MEDIUM

XML Entity Injection - Info Disclosure

Title source: llm
STIX 2.1

Description

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25.

Scores

CVSS v3 4.9
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
Keysight/Ixia Vision Product Family 6.3.1
Published Mar 05, 2025
Tracked Since Feb 18, 2026