Security Advisory

CVE-2024-14034

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-02 20:01:23
Last updated 2026-05-14 02:07:13
Assigner VulnCheck
State PUBLISHED

Description

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.