Status: UPDATED
| Advisory ID: CVE-2018-25236
Key Details
| CVE | CVE-2018-25236 |
| CVSS Score / Version | 9.8 (Critical) / CVSS v3.1 |
| Updated | 2026-07-21 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Belden Hirschmann HiSecOS EAGLE and Belden Hirschmann HiOS |
| Classified as | CWE-287 (Improper Authentication) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials. (NVD)
What to Do
Monitor Belden's web page for any future patch releases.
References