CVE-2020-6994
Estado: ModificadaCrítica (9.8)—
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.65%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-12
- CWE-120
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-6994",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Hirschmann Automation and Control GmbH, a division of Belden Inc.",
"product": "HiOS for the following devices RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED",
"versions": [
{
"status": "affected",
"version": "07.0.02 and lower"
}
]
},
{
"vendor": "Hirschmann Automation and Control GmbH, a division of Belden Inc.",
"product": "HiSecOS for device EAGLE20/30",
"versions": [
{
"status": "affected",
"version": "03.2.00 and lower"
}
]
}
]
}
],
"published": "2020-04-03T19:15:13.250",
"references": [
{
"url": "https://www.us-cert.gov/ics/advisories/icsa-20-091-01",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.us-cert.gov/ics/advisories/icsa-20-091-01",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-12"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30."
},
{
"lang": "es",
"value": "Se detectó una vulnerabilidad de desbordamiento de búfer en algunos dispositivos de Hirschmann Automation and Control HiOS y HiSecOS. La vulnerabilidad es debido al análisis inapropiado de los argumentos de la URL. Un atacante podría explotar esta vulnerabilidad mediante peticiones HTTP especialmente diseñadas para desbordar un búfer interno. Los siguientes dispositivos que usan HiOS Versión 07.0.02 y anteriores están afectados: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. Los siguientes dispositivos que usan HiSecOS Versión 03.2.00 y anteriores están afectados: EAGLE20 / 30."
}
],
"lastModified": "2026-06-17T03:24:05.270",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B3DB8FD-EC62-46F4-B60F-F71F3177730B",
"versionEndIncluding": "07.0.02"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:belden:hirschmann_embedded_ethernet_switch:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3CB779E6-113B-4430-905F-427FC87A61D8"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_embedded_ethernet_switch_extended:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E0EF2CF9-2150-4750-8DD6-9A911A187F34"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_greyhound_swtich:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2969C04A-B6C8-4F91-921A-5E13491329F0"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_mice_switch_power:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "74C8EBA4-96AB-4A40-B6FD-6A7C44C1F4FF"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_octopus:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4F849F79-6A81-433E-AF58-B745D177837C"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_prp_redbox:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7678F652-5260-4A81-931B-D5F2B4F91A66"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_rail_switch_power:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "992A605B-5B55-433C-A4E5-C9725C263FB3"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_rail_switch_power_enhanced:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ACC46D0A-4F92-41C7-B069-5047526CDCDF"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_rail_switch_power_lite:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FDE06D94-B686-4468-86CF-AA68BB5CFEF4"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_rail_switch_power_smart:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BC6487F7-284A-40C2-B70D-9380AD2A47C1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:belden:hirschmann_hisecos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B26FD56D-F11E-4990-A329-DBC18F40EFDE",
"versionEndIncluding": "03.2.00"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:belden:hirschmann_eagle20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "771189D9-34F0-400D-938B-2AA218C28C43"
},
{
"criteria": "cpe:2.3:h:belden:hirschmann_eagle30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3DCF228A-F3A8-4B36-A105-04E88980BA76"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}