CVE Vulnerabilities

CVE-2021-27734

Improper Authentication

Published: May 17, 2021 | Modified: Jul 12, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Hirschmann_hios Belden 08.1.00 (including) 08.6.00 (excluding)
Hirschmann_hios Belden 07.1.01 (including) 07.1.01 (including)
Hirschmann_hios Belden 07.1.02 (including) 07.1.02 (including)
Hisecos Belden 03.3.00 (including) 03.5.01 (including)

Potential Mitigations

References