Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.
References
Configurations
No configuration.
History
03 Apr 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Apr 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification. |
02 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 20:16
Updated : 2026-04-03 23:17
NVD link : CVE-2024-14034
Mitre link : CVE-2024-14034
CVE.ORG link : CVE-2024-14034
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
