Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in Hirschmann HiLCOS OpenBAT and BAT450 products that impacts how they handle IPv6 IPsec VPN connections. This issue could allow unauthorized traffic to bypass security measures, potentially exposing sensitive network communications. The main concern at this time is confirming if these specific products are in use and, if so, understanding the potential exposure.
- Issue: Firewall bypass in VPN connections.
- Why remember: Affects industrial network gateways.
- Executive takeaway: Confirm if these devices are deployed.
Attack Path
How an attacker could exploit the issue
An attacker could bypass firewall rules by establishing both an IPv6 IPsec connection and an independent IPv6 internet connection. This would allow them to circumvent the device's security policies and potentially reach internal systems.
- No authentication or user interaction needed.
- Malicious traffic is sent over IPsec and IPv6.
- Allows VPN traffic to bypass firewall rules.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a firewall bypass vulnerability in IPv6 IPsec deployments could allow unauthenticated attackers to circumvent configured firewall rules for VPN connections. This could expose network traffic that is intended to be protected by the firewall.
- VPN traffic could be exposed.
- Attackers could bypass firewall rules.
- Unintended network access may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Hirschmann HiLCOS OpenBAT and BAT450 products, specifically within IPv6 IPsec deployments. Responsibility for addressing this will likely fall to network infrastructure or security operations teams responsible for edge devices and VPN configurations. The initial action should be to identify all instances of these products, determine their network exposure and criticality, and then confirm the accountable system owner before planning remediation.
- Network and security teams should own the issue.
- Verify product deployment and network exposure.
- Plan remediation based on identified risk.