Executive brief
A security vulnerability exists in Hirschmann EagleSDV industrial security appliances. An attacker can cause the device to crash and stop functioning by attempting to connect using older, insecure encryption standards (TLS 1.0 or 1.1). This results in a denial of service, potentially disrupting industrial network traffic and security monitoring until the device is recovered.
Technical details
The vulnerability is classified as uncontrolled resource consumption (CWE-400) within the TLS implementation of Hirschmann EagleSDV firmware. Specifically, the device fails to properly handle session establishment requests when the client specifies TLS 1.0 or TLS 1.1 protocols, leading to a system crash. This is a network-reachable vulnerability that requires no authentication or user interaction to exploit. An attacker can repeatedly trigger this condition to maintain a denial-of-service state. The issue is resolved in firmware version 05.4.02.
Affected products
- Hirschmann EagleSDV 05.4.01 prior to 05.4.02
Timeline
- 2026-04-02: disclosed: Initial disclosure by VulnCheck and Belden
- 2026-04-02: advisory: NVD publication date