CVE-2018-25236
Hirschmann HiOS and HiSecOS HTTP(S) Management Authentication Bypass
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An authentication bypass vulnerability exists in the HTTP(S) management module of Hirschmann HiOS and HiSecOS products, allowing unauthenticated remote attackers to gain administrative access by crafting special HTTP requests. This could lead to unauthorized control over network services.