Buffer Overflow Vulnerability in Hirschmann HiSecOS Devices
CVE-2018-25237

9.3CRITICAL

What is CVE-2018-25237?

Hirschmann HiSecOS devices prior to version 05.3.03 are impacted by a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled. This issue occurs when a password longer than 128 characters is submitted, allowing remote attackers to improperly manage bounds in password handling. As a result, this exploitation can lead to device crashes or potentially enable the execution of arbitrary code, compromising the device's integrity and availability.

Affected Version(s)

Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One) 05.3.03

Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One) 0 <= 05.3.02

Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One) 05.3.03

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.