Impact
A flaw in the EagleSDV firmware causes a crash when a TLS 1.0 or TLS 1.1 handshake is attempted during session setup. The resulting denial-of-service blocks device management and normal operation, compromising availability for users who rely on the device for logging and control. The weakness corresponds to uncontrolled resource consumption triggered without authentication.
Affected Systems
Belden Hirschmann EagleSDV devices running firmware version 05.4.01 or earlier. Versions 05.4.02 and later contain the fix. All networked units that accept TLS connections are affected.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity. The EPSS score is less than 1%, suggesting a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker with network access can trigger the crash by initiating a TLS 1.0 or TLS 1.1 connection, so the attack vector is remote and does not require privileged credentials.
OpenCVE Enrichment