CVE-2023-7342 is a high-severity privilege escalation vulnerability (CVSS 8.8) affecting HiSecOS web server versions 03.4.00 prior to 04.1.00. It allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted network packets. This low-complexity attack requires no user interaction and can lead to full administrative control of the affected device. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, indicating no active exploitation. Community discussion regarding this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Belden | Hirschmann HiSecOS EAGLE | >= 03.4.00, <= 04.1.00CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.