Junglewise Threat Intelligence

CVE-2023-7342: Belden Hirschmann HiSecOS privilege escalation in web server

CVE-2023-7342 · Severity: high · CVSS 8.8 · Published 2026-04-02

Executive brief

A vulnerability in the web management interface of Belden Hirschmann HiSecOS EAGLE devices allows users with low-level access to take full control of the system. By sending specially crafted network requests, an authenticated operator or auditor can bypass security restrictions to gain administrative privileges. This could lead to unauthorized configuration changes, service disruption, or full compromise of the industrial networking equipment.

Technical details

A privilege escalation vulnerability (CWE-269) exists in the HiSecOS web server component of Hirschmann HiSecOS EAGLE devices. The flaw is rooted in improper privilege management, allowing an authenticated attacker with low-privileged roles (such as 'operator' or 'auditor') to escalate their permissions to 'administrator' by sending specially crafted packets to the web server. This attack is reachable over the network and does not require user interaction beyond the initial authentication. Successful exploitation grants the attacker full administrative control over the affected device. The vulnerability is addressed in version 04.1.00.

Affected products

  • Belden (Hirschmann) HiSecOS EAGLE 03.4.00 prior to 04.1.00

Timeline

  • 2026-04-02: advisory: Initial advisory published by VulnCheck and Belden

References