← All Advisories

CVE-2023-7342

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2023-7342

Key Details

CVECVE-2023-7342
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-07-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBelden Hirschmann HiSecOS EAGLE
Classified asCWE-269 (Improper Privilege Management)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BeldenHirschmann HiSecOS EAGLE
SubsystemsGeneral OT
SectorsMultiple

What to Know

HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw to gain full administrative access to the affected device. (NVD)

What to Do

Monitor Belden's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-7342
CVEhttps://www.cve.org/CVERecord?id=CVE-2023-7342