UNKNOWNCVE-2018-25236

Hirschmann HiOS HiSecOS Authentication Bypass via HTTP Management

Platform

other

Component

hirschmann-hios-hisecos

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials.

How to fix

Actualice Hirschmann HiOS/HiSecOS a una versión no vulnerable. Consulte el boletín de seguridad del proveedor para obtener más detalles e instrucciones específicas de actualización.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free