CVE-2024-14033: Hirschmann EagleSDV Denial of Service via TLS
Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device during TLS handshake by exploiting protocol downgrades to TLS 1.0 or TLS 1.1, interrupting service availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-14033?
CVE-2024-14033 has been assessed as a high severity vulnerability due to its potential to be exploited by unauthenticated remote attackers to trigger a denial of service.
How do I fix CVE-2024-14033?
To mitigate CVE-2024-14033, it is recommended to update the affected Hirschmann products to the latest patched version.
Which Hirschmann products are affected by CVE-2024-14033?
CVE-2024-14033 affects various Hirschmann products including EagleSDV, HiLCOS, BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, and BAT Controller Virtual.
Can CVE-2024-14033 be exploited remotely?
Yes, CVE-2024-14033 can be exploited remotely by unauthenticated attackers.
What is the impact of CVE-2024-14033?
The impact of CVE-2024-14033 is a denial of service condition, which can disrupt the availability of affected systems.