Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Belden

First CVE: Feb 18, 2016Active for: 10 yearsTotal CVEs: 33
45.0
VTI Score
High

Belden manufactures industrial networking and communications equipment, with a substantial vulnerability footprint concentrated in automation and rail infrastructure products such as its Hirschmann HIOS controllers, Eagle switching platforms, and Rail Switch Power family. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward public exploit availability, reflecting the memory-safety and cryptographic-validation demands of embedded industrial control systems. The exposure recurs through weakness classes including buffer overflows, information disclosure, improper cryptographic verification, and session-fixation flaws that arise in firmware and network management interfaces often deployed in safety-critical environments. Defenders should prioritize Belden device inventory and segregation in industrial control networks, as remediation cycles in these environments typically extend beyond standard patch windows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Belden over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2016
10 years ago
Most Recent CVE
Apr 3, 2026
112 days ago

Products(208 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12255CRITICAL
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
Aug 9, 20199.881NOYES
CVE-2019-12257HIGH
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh
Aug 9, 20198.874NONO
CVE-2019-12258HIGH
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
Aug 9, 20197.548NOYES
CVE-2019-12265MEDIUM
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3
Aug 9, 20195.348NONO
CVE-2019-12256CRITICAL
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
Aug 9, 20199.845NONO
CVE-2019-12260CRITICAL
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma
Aug 9, 20199.843NONO
CVE-2019-12261CRITICAL
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion dur
Aug 9, 20199.835NONO
CVE-2019-12259HIGH
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP pa
Aug 9, 20197.532NONO
CVE-2018-5469CRITICAL
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform S
Mar 6, 20189.832NONO
CVE-2019-12262CRITICAL
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Lo
Aug 14, 20199.831NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
30%
36%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (78.8%)
Unknown0 (0.0%)
Physical3 (9.1%)
Adjacent Network4 (12.1%)
Attack Complexity
Low29 (87.9%)
High4 (12.1%)
Unknown0 (0.0%)
User Interaction
None31 (93.9%)
Unknown0 (0.0%)
Required2 (6.1%)
Privileges Required
Low1 (3.0%)
High0 (0.0%)
None32 (97.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Belden.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Belden — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Belden's Products

View all 4 CNAs →

Top CWEs