PatchSiren cyber security CVE debrief
CVE-2025-21095 Keysight CVE debrief
CVE-2025-21095 is a Keysight Ixia Vision Product Family issue where path traversal may allow arbitrary file download. CISA’s advisory lists the affected product as Keysight Ixia Vision Product Family 6.3.1 and notes remediation in version 6.8.0. The advisory also states that, in combination with other issues, this flaw may help further compromise the device.
- Vendor
- Keysight
- Product
- Ixia Vision Product Family
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-04
- Original CVE updated
- 2025-09-30
- Advisory published
- 2025-03-04
- Advisory updated
- 2025-09-30
Who should care
Organizations operating Keysight Ixia Vision Product Family deployments, especially any instance running version 6.3.1 or older, as well as OT/ICS administrators, vulnerability managers, and teams responsible for controlling access to management interfaces.
Technical summary
The source CSAF advisory describes a path traversal weakness that may enable arbitrary download of files. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N, which yields a 4.9 medium severity score and reflects that elevated privileges are required. CISA further notes that the issue can contribute to further compromise when combined with other vulnerabilities. Remediation is available in version 6.8.0.
Defensive priority
Medium; prioritize upgrade if the product is exposed to broader administrative access or could be chained with other weaknesses.
Recommended defensive actions
- Upgrade Keysight Ixia Vision Product Family to version 6.8.0 or later as soon as practical.
- Inventory deployments to confirm whether version 6.3.1 or earlier is in use.
- Restrict administrative access to the device and follow least-privilege principles for all management accounts.
- Apply CISA ICS recommended practices and review file access activity for unusual download behavior.
Evidence notes
CISA’s CSAF advisory ICSA-25-063-02, published 2025-03-04, identifies CVE-2025-21095 and the affected product as Keysight Ixia Vision Product Family: 6.3.1. The advisory states that remediation is available in version 6.8.0, released on 2025-03-01. The CVSS information provided in the source is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N with a score of 4.9. The advisory revision history shows Update A on 2025-09-30 added CVE-2025-24525 and did not change the core description of this issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21095 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21095
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21095 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21095
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-063-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.