CVE-2022-4986: Hirschmann EagleSDV Denial of Service via TLS
Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann EagleSDVto a version that resolves this vulnerability.Fixed in 05.4.02 - Configuration
To reduce denial-of-service risk during session establishment, disable TLS 1.0 and TLS 1.1 on Hirschmann EagleSDV until devices are upgraded to 05.4.02 or later.
Hirschmann EagleSDV (TLS) TLS protocol versions = Disable TLS 1.0 and TLS 1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4986?
CVE-2022-4986 has a severity rating that indicates a denial-of-service vulnerability allowing device crashes.
How do I fix CVE-2022-4986?
To fix CVE-2022-4986, update Hirschmann EagleSDV to version 05.4.02 or later.
What versions of Hirschmann EagleSDV are affected by CVE-2022-4986?
CVE-2022-4986 affects Hirschmann EagleSDV versions prior to 05.4.02.
What type of vulnerability is CVE-2022-4986?
CVE-2022-4986 is a denial-of-service vulnerability that occurs during TLS session establishment.
Can CVE-2022-4986 be exploited remotely?
Yes, CVE-2022-4986 can be exploited remotely by initiating TLS connections that trigger the crash.