CVE Database
/

CVE-2020-6994

Back to search

CVE-2020-6994

Published: Apr 3, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

VendorProductVersions

Hirschmann Automation and Control GmbH, a division of Belden Inc.

HiOS for the following devices RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED

affected
07.0.02 and lower

Hirschmann Automation and Control GmbH, a division of Belden Inc.

HiSecOS for device EAGLE20/30

affected
03.2.00 and lower

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now