Belden Hirschmann's vulnerability exposure centers on its Gecko Lite managed switch product line, which provides network infrastructure and management capabilities in industrial and enterprise environments. The observed weakness classes—including cross-site request forgery, server-side request forgery, sensitive information exposure, and path traversal—reflect the web-management interface and access-control demands typical of networked switching and infrastructure appliances. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Belden Hirschmann over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6036MEDIUM A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does no | Jun 30, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-5163MEDIUM An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the conf | Feb 13, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-6040MEDIUM An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymousl | Jun 30, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-6038HIGH A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verif | Jun 30, 2017 | 7.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Belden Hirschmann.
Media articles that mention a CVE ID that affects a product developed by Belden Hirschmann — matched by CVE ID, not by vendor name.