CVE-2024-14034 PUBLISHED

Hirschmann HiEOS Authentication Bypass via HTTP Management Module

Assigner: VulnCheck
Reserved: 01.04.2026 Published: 02.04.2026 Updated: 03.04.2026

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Belden
Product Hirschmann HiEOS LRS11
Versions Default: unaffected
  • affected from 0 to 01.1.00 (excl.)

References

Problem Types

  • Improper Authentication (CWE-287) CWE