CVE-2023-7342
Received
Received - Intake
Privilege Escalation in HiSecOS Web Server Allows Admin Access
Publication date: 2026-04-02
Last updated on: 2026-04-02
Assigner: VulnCheck
Description
Description
HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw to gain full administrative access to the affected device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hirschmann | hisecos_eagle | From 03.4.00 (inc) to 04.0.xx (inc) |
| hirschmann | hisecos_eagle | 04.1.00 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |