Hirschmann HiOS 交换机平台设备中集成的 Web 服务器存在一个拒绝服务(DoS)漏洞,原因是未对 HTTP(S) 内容进行验证。未经身份验证的远程攻击者可以向某个特定端点发送经过特别构造的 HTTP(S) 请求,由于该请求被错误处理,将导致设备发生意外重启,从而引发临时的拒绝服务状态。该漏洞已在以下版本中修复:07.1.12、08.7.10、09.0.13、09.3.03、10.3.08 和 10.5.00。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Belden | Hirschmann HiOS Switch Platform | 07.0.0≤ 07.1.11 |
affected |
07.1.12 |
unaffected | ||
08.0.0≤ 08.7.09 |
affected | ||
08.7.10 |
unaffected | ||
09.0.00≤ 09.0.12 |
affected | ||
09.0.13 |
unaffected | ||
09.3.00≤ 09.3.02 |
affected | ||
09.3.03 |
unaffected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Belden | Hirschmann HiOS Switch Platform | 07.0.0 ~ 07.1.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet