CVE-2024-14034

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.
Configurations

No configuration.

History

03 Apr 2026, 23:17

Type Values Removed Values Added
References
  • () https://www.vulncheck.com/advisories/hirschmann-hieos-authentication-bypass-via-http-management-moduleĀ -

02 Apr 2026, 23:17

Type Values Removed Values Added
Summary (en) Hirschmann HiEOS devices contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification. (en) Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.

02 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 20:16

Updated : 2026-04-03 23:17


NVD link : CVE-2024-14034

Mitre link : CVE-2024-14034

CVE.ORG link : CVE-2024-14034


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication