Belden HiSecOS
cpe:2.3:o:belden:hirschmann_hisecos:*:*:*:*:*:*:*
- <= 04.0.01
A privilege escalation vulnerability exists in HiSecOS version 04.0.01, allowing authenticated users to alter their access roles via XML-based NETCONF configuration. By sending specially crafted XML payloads to the /mops_data endpoint, users can elevate their privileges to administrative levels.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling users to gain administrative rights.
To reproduce this vulnerability, an authenticated user must send a POST request to the /mops_data endpoint with an XML payload that includes a specific role value. The payload must be crafted to modify the user's access role to 'admin'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.