CVE-2020-6994CWE-12

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS

published April 3, 2020

CVSS
EPSS
2%
Percentile
74.8
In the wild
Unconfirmed
What it is

⚠️ A crafty HTTP request is all it takes to trigger this buffer overflow in Hirschmann devices! They’re affected by a parsing quirk that lets attackers overflow internal memory - yikes! 🔥 Think of it like a waiter at a restaurant who misreads the menu and delivers an order with double the ingredients, overwhelming the kitchen's capacity. That can lead to chaos behind the scenes! If exploited, an attacker could send specially crafted requests that overflow the device's internal buffer, potentially causing crashes or erratic behavior. This means your critical automation controls might act unpredictably, risking downtime and operational efficiency.

Put simply

Think of it like a waiter at a restaurant who misreads the menu and delivers an order with double the ingredients, overwhelming the kitchen's capacity. That can lead to chaos behind the scenes! This vulnerability arises from improper parsing of URL arguments in devices running HiOS Version 07.0.02 and lower, and HiSecOS Version 03.2.00 and lower. An attacker can trigger a buffer overflow by sending malicious HTTP requests, affecting device stability.

What to do

If exploited, an attacker could send specially crafted requests that overflow the device's internal buffer, potentially causing crashes or erratic behavior. This means your critical automation controls might act unpredictably, risking downtime and operational efficiency. To protect your devices, update to the latest firmware versions available for HiOS and HiSecOS. Ensure that any vulnerable devices, like RSP, RSPE, and EAGLE20/30, are patched to mitigate this parsing issue. Regularly audit your systems for vulnerabilities to stay ahead! You've got this! With a little diligence and these updates, your systems can stay safe and sound! 🛡️

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.01646 · 74.8th percentile
Weakness
CWE-12 · ASP.NET Misconfiguration: Missing Custom Error Page
Published
2020-04-03T18:04Z
EPSS history
Timeline
  • 03 APR 18:04Z
    A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS
    cvelistv5