Description
Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.
Problem types
CWE-400: Uncontrolled Resource Consumption
Product status
05.4.02 (custom)
Any version before 05.4.01
References
assets.belden.com/...den_Security_Bulletin_BSECV-2022-08.pdf
www.vulncheck.com/...mann-eaglesdv-denial-of-service-via-tls