CVE-2021-27734Improper Authentication in Hirschmann Hios

Severity
9.8CRITICALNVD
EPSS
0.1%
top 69.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 24

Description

Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDbelden/hirschmann_hios08.1.0008.6.00+2
NVDbelden/hisecos03.3.0003.5.01

🔴Vulnerability Details

2
GHSA
GHSA-r6q8-h627-r6p2: Hirschmann HiOS 072022-05-24
CVEList
CVE-2021-27734: Hirschmann HiOS 072021-05-17
CVE-2021-27734 — Improper Authentication | cvebase