Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can inject or observe multicast and broadcast packets that should have been blocked by the firewall.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Belden
Belden hirschmann Hilcos Bat450 Belden hirschmann Hilcos Bat867 Belden hirschmann Hilcos Openbat Belden hirschmann Hilcos Wlc |
|
| Vendors & Products |
Belden
Belden hirschmann Hilcos Bat450 Belden hirschmann Hilcos Bat867 Belden hirschmann Hilcos Openbat Belden hirschmann Hilcos Wlc |
Mon, 06 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can inject or observe multicast and broadcast packets that should have been blocked by the firewall. | |
| Title | Hirschmann HiLCOS Layer-2 Firewall Multicast Broadcast Traffic Bypass | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-03T22:47:07.496Z
Updated: 2026-04-06T16:50:39.698Z
Reserved: 2026-04-03T17:40:03.508Z
Link: CVE-2017-20233
Updated: 2026-04-06T16:50:29.107Z
Status : Awaiting Analysis
Published: 2026-04-03T23:16:59.763
Modified: 2026-04-07T13:20:55.200
Link: CVE-2017-20233
No data.