July 21, 2026

Overview

Keysight recently became aware of one critical (CVE-2026-49435) and two high severity (CVE-2017-20242, CVE-2017-20241) vulnerabilities at the IxChariot product code base.

The issues potentially allow full compromise of the target system through arbitrary code execution without any user interaction or privileges required.

If exploited, this vulnerability could allow a sophisticated attacker to execute code remotely. Keysight is not currently aware of malicious exploitation of the vulnerability and will continue to monitor the situation.

These issues were disclosed to Keysight by the Agence nationale de la sécurité des systèmes d'information (ANSSI) who reported them on behalf of Sébastien Charbonnier. Keysight would like to thank Sébastien Charbonnier and ANSSI for their assistance.

Issues CVE-2017-20242 and CVE-2017-20241 reported by the researcher were previously resolved by Keysight in 2017 as part of standard product maintenance. At that time, they were treated as functional defects rather than security vulnerabilities.

 

Impacted Products and Mitigation

We have assessed the complete Keysight product portfolio available as of this time and determined that, besides IxChariot, Hawkeye and some network probe products are also impacted by CVE-2026-494351.

Details and appropriate mitigation information can be found below:

VulnerabilityProductMitigation
CVE-2017-20242 &
CVE-2017-20241
IxChariot Endpoint versions
older than 9.5.102
IxChariot Endpoint version 9.5.102
(released 11 August, 2017 as bug fixes)
CVE-2026-49435IxChariot Endpoint versions
older than 10.0.254
IxChariot Endpoint version 10.0.254 (released 30 April, 2026)
Hawkeye versions older
than 6.0.7
Hawkeye version 6.0.7 (released 26 June, 2026)
IxProbe/IxTap/IxByPass versions
older than 3.13.0
IxProbe/IxTap/IxByPass version 3.13.0 (released 26 June, 2026)

 

Recommended Action

Keysight recommends that all customers upgrade to the latest version of software as soon as possible. Older versions of software may have these vulnerabilities; we recommend that customers discontinue the use of older software versions.

In general, Keysight recommends that customers always follow industry cybersecurity best practices and always update to the latest software versions available to them to safeguard against any vulnerabilities and threats.

For additional questions, please contact Keysight

1 Keysight used commercially reasonable efforts to compile the list of products affected by the IxChariot vulnerability. Keysight offers this information for your convenience and does not warrant it is complete.

Want help or have questions?