Impact
The flaw in the Hirschmann HiOS Switch Platform web server is a missing validation of HTTP(S) content, identified as CWE‑755. A remote, unauthenticated attacker can send a specially crafted request to a particular endpoint. The server parses the malformed payload incorrectly, causing the device to reboot unexpectedly. This reboot disables network connectivity for a short time, producing a temporary denial‑of‑service condition.
Affected Systems
The vulnerability affects Hirschmann HiOS Switch Platform devices sold by Belden. Firmware releases up to (but not including) 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00 contain the fix; older firmware versions are considered vulnerable.
Risk and Exploitability
With a CVSS score of 8.7, the issue is classified as high severity, indicating that any exposed device can be disrupted without authentication. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, yet its straightforward remote exploitation path and the ability to interrupt network services place it at significant risk for exposed switches. An attacker only needs to issue a malformed HTTP request to trigger a reboot, so hardening network perimeter controls or blocking the affected web endpoint remains critical until a patch can be applied.
OpenCVE Enrichment