7.5
CVE-2026-89025
- EPSS 0.42%
- Veröffentlicht 15.09.2026 14:13:26
- Zuletzt bearbeitet 24.09.2026 20:44:42
- Erkennungen
Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerBelden
≫
Produkt
Hirschmann HiOS Switch Platform
Default Statusunaffected
Version <=
07.1.11
Version
07.0.0
Status
affected
Version
07.1.12
Status
unaffected
Version <=
08.7.09
Version
08.0.0
Status
affected
Version
08.7.10
Status
unaffected
Version <=
09.0.12
Version
09.0.00
Status
affected
Version
09.0.13
Status
unaffected
Version <=
09.3.02
Version
09.3.00
Status
affected
Version
09.3.03
Status
unaffected
Version <=
10.3.07
Version
10.0.0
Status
affected
Version
10.3.08
Status
unaffected
Version
10.4.00
Status
affected
Version
10.5.00
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.36 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
https://assets.belden.com/asset/2ba884e3-c0c9-40f6-aa22-a9e852b20af4/PSIRT-6_HTTPS_Vulnerability_HiOS.pdf
https://www.vulncheck.com/advisories/hirschmann-hios-switch-platform-dos-via-malformed-http-request