External risk intelligence

Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2021-4477

The vulnerability affects industrial networking devices (OpenBAT/BAT450) specifically in their role as VPN gateways and firewalls. Because these products are designed to act as internet-facing or edge-connecting network infrastructure for industrial communications, they are commonly deployed where they are reachable via public-facing network services.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Hirschmann HiLCOS OpenBAT and BAT450 products that impacts how they handle IPv6 IPsec VPN connections. This issue could allow unauthorized traffic to bypass security measures, potentially exposing sensitive network communications. The main concern at this time is confirming if these specific products are in use and, if so, understanding the potential exposure.

  • Issue: Firewall bypass in VPN connections.
  • Why remember: Affects industrial network gateways.
  • Executive takeaway: Confirm if these devices are deployed.

Attack Path

How an attacker could exploit the issue

An attacker could bypass firewall rules by establishing both an IPv6 IPsec connection and an independent IPv6 internet connection. This would allow them to circumvent the device's security policies and potentially reach internal systems.

  • No authentication or user interaction needed.
  • Malicious traffic is sent over IPsec and IPv6.
  • Allows VPN traffic to bypass firewall rules.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a firewall bypass vulnerability in IPv6 IPsec deployments could allow unauthenticated attackers to circumvent configured firewall rules for VPN connections. This could expose network traffic that is intended to be protected by the firewall.

  • VPN traffic could be exposed.
  • Attackers could bypass firewall rules.
  • Unintended network access may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Hirschmann HiLCOS OpenBAT and BAT450 products, specifically within IPv6 IPsec deployments. Responsibility for addressing this will likely fall to network infrastructure or security operations teams responsible for edge devices and VPN configurations. The initial action should be to identify all instances of these products, determine their network exposure and criticality, and then confirm the accountable system owner before planning remediation.

  • Network and security teams should own the issue.
  • Verify product deployment and network exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Hirschmann HiLCOS OpenBAT and BAT450?

These are industrial-grade networking devices used to provide reliable connectivity in challenging environments. They function as wireless access points and routers, often serving as gateways for industrial communications. They support VPN configurations to secure data transmission, making them critical components for maintaining network segmentation and security in automated or remote operational settings.

What does the firewall bypass mean in CVE-2021-4477?

This vulnerability, classified as CWE-284 (Improper Access Control), describes a flaw in how the device handles traffic rules. Essentially, the software fails to correctly enforce security policies for certain encrypted connections. Because the firewall logic is circumvented, traffic that should be blocked or filtered by security rules is allowed to pass through, potentially giving unauthorized parties access to protected internal network segments.

How does an attacker trigger this vulnerability?

An attacker initiates the bypass by establishing an IPv6 IPsec VPN connection while simultaneously using an IPv6 internet connection. The bug relies on this specific combination of concurrent connection types to confuse the firewall's policy enforcement mechanism. Note that standard IPv4 traffic or non-VPN connections do not trigger this specific flaw; the path requires the device to be actively processing the vulnerable IPv6 IPsec configuration.

Who should be concerned about this CVE?

Organizations using Hirschmann OpenBAT or BAT450 devices in their network architecture should prioritize this issue. According to Halo Surface Signal, because these products are designed as industrial gateways and VPN endpoints, they are frequently deployed in edge-facing roles where they are reachable via public-facing services. If your devices are configured to accept IPv6 IPsec connections from the internet, the potential for unauthorized access is significantly higher.

How do I respond to this vulnerability?

The first step is to conduct an inventory to locate all deployed HiLCOS OpenBAT and BAT450 devices within your infrastructure. Once identified, review your current network configurations to determine if IPv6 and IPsec are enabled. After assessing the exposure of these specific units, coordinate with the responsible network infrastructure team to verify the risk level and plan subsequent mitigation steps or configuration adjustments to secure the traffic flow.

References