← Back

CVE-2020-6994

nvd nist
Published: Apr 3, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

Affected (2)

2 products
Hirschmann Hios
Hirschmann Hisecos
Configuration A
1 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Up to 07.0.02
Running on/withPlatform Versions
Belden
Hirschmann Embedded Ethernet Switch
All versions
Belden
Hirschmann Embedded Ethernet Switch Extended
All versions
Belden
Hirschmann Greyhound Swtich
All versions
Belden
Hirschmann Mice Switch Power
All versions
Belden
Hirschmann Octopus
All versions
Belden
Hirschmann Prp Redbox
All versions
Belden
Hirschmann Rail Switch Power
All versions
Belden
Hirschmann Rail Switch Power Enhanced
All versions
Belden
Hirschmann Rail Switch Power Lite
All versions
Belden
Hirschmann Rail Switch Power Smart
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Up to 03.2.00
Running on/withPlatform Versions
Belden
Hirschmann Eagle20
All versions
Belden
Hirschmann Eagle30
All versions

References (2)

Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.