Advisories

Hirschmann Industrial IT HiLCOS Heap Overflow DoS

Go Back
severity
high
date
Affecting
  • Hirschmann HiLCOS BAT-R 10.34.6313 < 10.34.6464

  • Hirschmann HiLCOS BAT-F 10.34.6313 < 10.34.6464

  • Hirschmann HiLCOS BAT450-F 10.34.6313 < 10.34.6464

  • Hirschmann HiLCOS BAT867-R 10.34.6313 < 10.34.6464

  • Hirschmann HiLCOS BAT867-F 10.34.6313 < 10.34.6464

  • Hirschmann HiLCOS WLC 10.34.6313 < 10.34.6464

  • Hirschmann HiLCOS BAT Controller Virtual 10.34.6313 < 10.34.6464

CWE
  • CWE-122: Heap-based Buffer Overflow
CVSS
8.7
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to the web interface. Attackers can exploit this heap overflow to crash the affected device and cause service disruption, particularly in configurations where the Public Spot functionality is enabled.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.