CVE-2024-14034: Hirschmann HiEOS Authentication Bypass via HTTP Management Module
Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann HiEOSto a version that resolves this vulnerability.Fixed in 01.1.00
Event History
Frequently Asked Questions
What is the severity of CVE-2024-14034?
CVE-2024-14034 has been classified as a critical severity vulnerability.
How do I fix CVE-2024-14034?
To fix CVE-2024-14034, upgrade Hirschmann HiEOS devices to version 01.1.00 or later.
What type of vulnerability is CVE-2024-14034?
CVE-2024-14034 is an authentication bypass vulnerability affecting the HTTP management module.
Who is affected by CVE-2024-14034?
CVE-2024-14034 affects Hirschmann HiEOS devices running versions prior to 01.1.00.
Can CVE-2024-14034 be exploited remotely?
Yes, CVE-2024-14034 can be exploited remotely by unauthenticated attackers.