← All Advisories

CVE-2024-14034

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2024-14034

Key Details

CVECVE-2024-14034
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBelden Hirschmann HiEOS LRS11
Classified asCWE-287 (Improper Authentication)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BeldenHirschmann HiEOS LRS11
SubsystemsGeneral OT
SectorsMultiple

What to Know

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification. (NVD)

What to Do

Monitor Belden's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-14034
CVEhttps://www.cve.org/CVERecord?id=CVE-2024-14034