Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to the web interface. Attackers can exploit this heap overflow to crash the affected device and cause service disruption, particularly in configurations where the Public Spot functionality is enabled.
References
Configurations
No configuration.
History
03 Apr 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
02 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CWE | CWE-400 | |
| Summary | (en) Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to the web interface. Attackers can exploit this heap overflow to crash the affected device and cause service disruption, particularly in configurations where the Public Spot functionality is enabled. |
02 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 21:16
Updated : 2026-04-03 23:17
NVD link : CVE-2024-14033
Mitre link : CVE-2024-14033
CVE.ORG link : CVE-2024-14033
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
