Description
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.
Published: 2020-04-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-28134 A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.
History

No history.

Subscriptions

Belden Hirschmann Eagle20 Hirschmann Eagle30 Hirschmann Embedded Ethernet Switch Hirschmann Embedded Ethernet Switch Extended Hirschmann Greyhound Swtich Hirschmann Hios Hirschmann Hisecos Hirschmann Mice Switch Power Hirschmann Octopus Hirschmann Prp Redbox Hirschmann Rail Switch Power Hirschmann Rail Switch Power Enhanced Hirschmann Rail Switch Power Lite Hirschmann Rail Switch Power Smart
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T09:18:02.906Z

Reserved: 2020-01-14T00:00:00.000Z

Link: CVE-2020-6994

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-03T19:15:13.250

Modified: 2024-11-21T05:36:27.270

Link: CVE-2020-6994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses