Status: UPDATED
| Advisory ID: CVE-2015-10148
Key Details
| CVE | CVE-2015-10148 |
| CVSS Score / Version | 8.2 (High) / CVSS v3.1 |
| Updated | 2026-07-21 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none. |
| Affected products | Belden Hirschmann HiLCOS |
| Classified as | CWE-321 (Use of Hard-coded Cryptographic Key) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-in-the-middle attacks, impersonate devices, and expose sensitive information by leveraging the shared default cryptographic keys across multiple devices. (NVD)
What to Do
Monitor Belden's web page for any future patch releases.
References