Belden manufactures industrial networking and communications equipment, with a substantial vulnerability footprint concentrated in automation and rail infrastructure products such as its Hirschmann HIOS controllers, Eagle switching platforms, and Rail Switch Power family. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward public exploit availability, reflecting the memory-safety and cryptographic-validation demands of embedded industrial control systems. The exposure recurs through weakness classes including buffer overflows, information disclosure, improper cryptographic verification, and session-fixation flaws that arise in firmware and network management interfaces often deployed in safety-critical environments. Defenders should prioritize Belden device inventory and segregation in industrial control networks, as remediation cycles in these environments typically extend beyond standard patch windows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Belden over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12255CRITICAL Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | Aug 9, 2019 | 9.8 | 81 | NO | YES |
CVE-2019-12257HIGH Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh | Aug 9, 2019 | 8.8 | 74 | NO | NO |
CVE-2019-12258HIGH Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | Aug 9, 2019 | 7.5 | 48 | NO | YES |
CVE-2019-12265MEDIUM Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 | Aug 9, 2019 | 5.3 | 48 | NO | NO |
CVE-2019-12256CRITICAL Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | Aug 9, 2019 | 9.8 | 45 | NO | NO |
CVE-2019-12260CRITICAL Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma | Aug 9, 2019 | 9.8 | 43 | NO | NO |
CVE-2019-12261CRITICAL Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion dur | Aug 9, 2019 | 9.8 | 35 | NO | NO |
CVE-2019-12259HIGH Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP pa | Aug 9, 2019 | 7.5 | 32 | NO | NO |
CVE-2018-5469CRITICAL An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform S | Mar 6, 2018 | 9.8 | 32 | NO | NO |
CVE-2019-12262CRITICAL Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Lo | Aug 14, 2019 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Belden.
Media articles that mention a CVE ID that affects a product developed by Belden — matched by CVE ID, not by vendor name.