← Back

Hirschmann Hios

hirschmann_hios

Vendor: Belden • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Belden
2Hirschmann Hios
Hisecos
Jun 17, 2026
May 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.
1Belden
1Hirschmann Hios
Jun 17, 2026
Feb 11, 2021
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop on one of the HSR ring ports of the device. This effectively breaks th...Show more
Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop on one of the HSR ring ports of the device. This effectively breaks the redundancy of the HSR ring. If the attacker can perform the same attack on a second device, the ring is broken into two parts (thus disrupting communication between devices in the different parts).Show less
1Belden
2Hirschmann Hios
Hirschmann Hisecos
Jun 17, 2026
Apr 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability...Show more
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.Show less
3Belden
SiemensWindriver
7Garrettcom Magnum Dx940e Firmware
Hirschmann HiosRuggedcom Win7000 Firmware+4 more
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
6Belden
NetappOracle+3 more
13Communications Eagle
E Series Santricity Os ControllerGarrettcom Magnum Dx940e Firmware+10 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
6Belden
NetappOracle+3 more
13Communications Eagle
E Series Santricity Os ControllerGarrettcom Magnum Dx940e Firmware+10 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
4Belden
SiemensSonicwall+1 more
119410 Power Meter Firmware
9810 Power Meter FirmwareGarrettcom Magnum Dx940e Firmware+8 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.
5Belden
NetappSiemens+2 more
10E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+7 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
3Belden
SiemensWindriver
7Garrettcom Magnum Dx940e Firmware
Hirschmann HiosRuggedcom Win7000 Firmware+4 more
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.1 HIGH· v3
4.8 MEDIUM· v2
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.