CVE-2023-34394: Keysight Geolocation Server

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.

Affected products

  • Keysight Geolocation Server: up to and including 2.4.2

Published 2023-07-19. Last modified 2026-06-17.