CVE-2020-6994
Published: Apr 3, 2020
Modified: Aug 4, 2024
Description
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.
| Vendor | Product | Versions |
|---|---|---|
Hirschmann Automation and Control GmbH, a division of Belden Inc. | HiOS for the following devices RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED | affected 07.0.02 and lower |
Hirschmann Automation and Control GmbH, a division of Belden Inc. | HiSecOS for device EAGLE20/30 | affected 03.2.00 and lower |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now