CVE-2022-4986 PUBLISHED

Hirschmann EagleSDV Denial of Service via TLS

Assigner: VulnCheck
Reserved: 02.04.2026 Published: 02.04.2026 Updated: 03.04.2026

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Belden
Product Hirschmann EagleSDV
Versions Default: unaffected
  • affected from 0 to 08.1.03 (incl.)
  • unaffected from 0 to 08.1.04 (excl.)
  • unaffected from 0 to 08.2.00 (excl.)

References

Problem Types

  • CWE-400: Uncontrolled Resource Consumption CWE