Belden GarrettCom Magnum 6K和Belden GarrettCom Magnum 10K都是美国Belden公司的一款模块化工业以太网交换机。 Belden GarrettCom Magnum 6K和Belden GarrettCom Magnum 10K存在信任管理问题漏洞,该漏洞源于身份验证机制中存在硬编码字符串,可能导致未经身份验证的攻击者绕过登录控制,从而访问管理功能和敏感交换机配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Belden | GarrettCom Magnum 6K and 10K Managed Switches | 0 ~ 4.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-20237 | 9.8 CRITICAL | Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution |
| CVE-2018-25237 | 9.8 CRITICAL | Hirschmann HiSecOS Buffer Overflow via HTTPS Login |
| CVE-2018-25236 | 9.8 CRITICAL | Hirschmann HiOS HiSecOS Authentication Bypass via HTTP Management |
| CVE-2021-4477 | 9.1 CRITICAL | Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass |
| CVE-2015-10148 | 8.2 HIGH | Hirschmann HiLCOS Hard-coded Credentials SSH SSL Keys |
| CVE-2016-15058 | 8.1 HIGH | Hirschmann HiLCOS Classic Platform Password Exposure via SNMP |
| CVE-2020-37216 | 7.5 HIGH | Hirschmann HiOS EtherNet/IP Stack Denial of Service |
| CVE-2022-4987 | 7.3 HIGH | Hirschmann Industrial HiVision External Application Path Hijacking Leading to Arbitrary Co |
| CVE-2017-20238 | 7.1 HIGH | Hirschmann Industrial HiVision Improper Authorization Privilege Escalation |
| CVE-2017-20233 | 5.4 MEDIUM | Hirschmann HiLCOS Layer-2 Firewall Multicast Broadcast Traffic Bypass |
No comments yet