← All Advisories

CVE-2018-25236

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2018-25236

Key Details

CVECVE-2018-25236
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBelden Hirschmann HiSecOS EAGLE and Belden Hirschmann HiOS
Classified asCWE-287 (Improper Authentication)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BeldenHirschmann HiSecOS EAGLE
BeldenHirschmann HiOS
SubsystemsGeneral OT
SectorsMultiple

What to Know

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials. (NVD)

What to Do

Monitor Belden's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2018-25236
CVEhttps://www.cve.org/CVERecord?id=CVE-2018-25236