PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21095 Keysight CVE debrief

CVE-2025-21095 is a Keysight Ixia Vision Product Family issue where path traversal may allow arbitrary file download. CISA’s advisory lists the affected product as Keysight Ixia Vision Product Family 6.3.1 and notes remediation in version 6.8.0. The advisory also states that, in combination with other issues, this flaw may help further compromise the device.

Vendor
Keysight
Product
Ixia Vision Product Family
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-04
Original CVE updated
2025-09-30
Advisory published
2025-03-04
Advisory updated
2025-09-30

Who should care

Organizations operating Keysight Ixia Vision Product Family deployments, especially any instance running version 6.3.1 or older, as well as OT/ICS administrators, vulnerability managers, and teams responsible for controlling access to management interfaces.

Technical summary

The source CSAF advisory describes a path traversal weakness that may enable arbitrary download of files. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N, which yields a 4.9 medium severity score and reflects that elevated privileges are required. CISA further notes that the issue can contribute to further compromise when combined with other vulnerabilities. Remediation is available in version 6.8.0.

Defensive priority

Medium; prioritize upgrade if the product is exposed to broader administrative access or could be chained with other weaknesses.

Recommended defensive actions

  • Upgrade Keysight Ixia Vision Product Family to version 6.8.0 or later as soon as practical.
  • Inventory deployments to confirm whether version 6.3.1 or earlier is in use.
  • Restrict administrative access to the device and follow least-privilege principles for all management accounts.
  • Apply CISA ICS recommended practices and review file access activity for unusual download behavior.

Evidence notes

CISA’s CSAF advisory ICSA-25-063-02, published 2025-03-04, identifies CVE-2025-21095 and the affected product as Keysight Ixia Vision Product Family: 6.3.1. The advisory states that remediation is available in version 6.8.0, released on 2025-03-01. The CVSS information provided in the source is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N with a score of 4.9. The advisory revision history shows Update A on 2025-09-30 added CVE-2025-24525 and did not change the core description of this issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21095 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21095

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21095 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21095

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-063-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.