← Vulnerability feed

Vulnerability record · CVE-2020-6994 · published 3 April 2020

CVE-2020-6994: Belden hirschmann hios classic buffer overflow vulnerability

Belden · Hirschmann Hios

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

9.8 CVSS 3.1 Critical EPSS 1.6% · top 24.5% CWE-12 · CWE-12CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.us-cert.gov/ics/advisories/icsa-20-091-01 MitigationThird Party AdvisoryUS Government Resource
https://www.us-cert.gov/ics/advisories/icsa-20-091-01 MitigationThird Party AdvisoryUS Government Resource

Track CVE-2020-6994 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27734Belden hirschmann hios improper authentication vulnerabilityHirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of…EPSS 1.3%9.8CVE-2019-12262Windriver vxworks vulnerabilityWind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unso…EPSS 4.1%9.8CVE-2019-12260Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…EPSS 23%9.8CVE-2019-12261Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…EPSS 9.0%9.8CVE-2019-12255VxWorks IPNET TCP urgent pointer integer underflow buffer overflowWind River VxWorks contains a buffer overflow in the TCP component of its IPNET network stack, triggered by a TCP Urgent Pointer value of 0 that caus…EPSS 75%analysed9.8CVE-2019-12256Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing o…EPSS 27%8.8CVE-2019-12257VxWorks IPNET DHCP client heap buffer overflow in Offer/ACK parsingWind River VxWorks 6.6 through 6.9 contains a heap buffer overflow in the IPNET DHCP client (ipdhcpc) while parsing DHCP Offer and ACK messages. Beca…EPSS 84%analysed8.1CVE-2019-12263Windriver vxworks race condition vulnerabilityWind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Poin…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2020-6994), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.