CVE-2021-4477: Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass
Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by establishing IPv6 IPsec connections (IKEv1 or IKEv2) while simultaneously using an IPv6 Internet connection to circumvent firewall policy enforcement.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the IPv6 IPsec firewall bypass by applying network-level restrictions (e.g., firewall/ACL/WAF controls) so traffic from IPv6 IPsec (IKEv1 or IKEv2) VPN connections cannot bypass configured firewall rules.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4477?
CVE-2021-4477 is considered a high severity vulnerability due to its potential to allow unauthorized traffic through a firewall.
How do I fix CVE-2021-4477?
To fix CVE-2021-4477, update the Hirschmann HiLCOS OpenBAT or BAT450 software to the latest version that addresses the firewall bypass issue.
What are the potential impacts of CVE-2021-4477?
The impact of CVE-2021-4477 includes unauthorized access to sensitive information and traversal of protected networks.
Who is affected by CVE-2021-4477?
CVE-2021-4477 affects users of Hirschmann HiLCOS OpenBAT and BAT450 products utilizing IPv6 IPsec deployments.
Can CVE-2021-4477 be exploited remotely?
Yes, CVE-2021-4477 can be exploited remotely by attackers to bypass firewall configurations via VPN connections.