CRITICAL · 9.8

CVE-2020-6994

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploi...

Vulnerability Description

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BeldenHirschmann Hios<= 07.0.02
BeldenHirschmann Embedded Ethernet Switch-
BeldenHirschmann Embedded Ethernet Switch Extended-
BeldenHirschmann Greyhound Swtich-
BeldenHirschmann Mice Switch Power-
BeldenHirschmann Octopus-
BeldenHirschmann Prp Redbox-
BeldenHirschmann Rail Switch Power-
BeldenHirschmann Rail Switch Power Enhanced-
BeldenHirschmann Rail Switch Power Lite-
BeldenHirschmann Rail Switch Power Smart-
BeldenHirschmann Hisecos<= 03.2.00
BeldenHirschmann Eagle20-
BeldenHirschmann Eagle30-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-6994?

CVE-2020-6994 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploi...

How severe is CVE-2020-6994?

CVE-2020-6994 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-6994?

Check the references section above for vendor advisories and patch information. Affected products include: Belden Hirschmann Hios, Belden Hirschmann Embedded Ethernet Switch, Belden Hirschmann Embedded Ethernet Switch Extended, Belden Hirschmann Greyhound Swtich, Belden Hirschmann Mice Switch Power.