Belden HiSecOS
cpe:2.3:o:belden:hirschmann_hisecos:*:*:*:*:*:*:*
- >= 05.0.00, <= 08.3.01
A privilege escalation vulnerability has been identified in the HiSecOS web server, allowing authenticated users with operator or auditor roles to elevate their privileges to that of an administrator. This is achieved by sending specially crafted packets to the web server. Exploitation of this vulnerability grants full administrative access to the affected device.
Exploitation of this vulnerability allows authenticated users to gain administrative privileges on the affected device, potentially leading to unauthorized access and control over the device's functions and settings.
Users are advised to update to Industrial HiVision version 08.3.02 or higher, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.