Hirschmann HiOS Switches Argument Injection or Modification (CVE-2019-12264)

high Tenable OT Security Plugin ID 502265

Synopsis

The remote OT asset is affected by a vulnerability.

Description

An attacker residing on the LAN may choose to hijack a DHCP-client session that requests an IPv4 address. The attacker can send a multicast IP-address in the DHCP offer/ack message, which the victim system then incorrectly assigns.

This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?49fa5c3a

http://www.nessus.org/u?c7d3d59d

https://support.f5.com/csp/article/K41190253

https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf

http://www.nessus.org/u?ce6391b3

Plugin Details

Severity: High

ID: 502265

Version: 1.3

Type: remote

Family: Tenable.ot

Published: 6/10/2024

Updated: 6/11/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 3.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2019-12264

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:belden:hirschmann_rsp20, cpe:/h:belden:hirschmann_rail_switch_power_lite, cpe:/h:belden:hirschmann_rspe37, cpe:/h:belden:hirschmann_rsp25, cpe:/h:belden:hirschmann_rsp35, cpe:/h:belden:hirschmann_rspe30, cpe:/h:belden:hirschmann_rail_switch_power_smart, cpe:/h:belden:hirschmann_rspe35, cpe:/h:belden:hirschmann_dragon_mach4500, cpe:/h:belden:hirschmann_dragon_mach4000, cpe:/h:belden:hirschmann_eagle_one, cpe:/h:belden:hirschmann_eagle20, cpe:/h:belden:hirschmann_eagle30, cpe:/h:belden:hirschmann_rsp30, cpe:/h:belden:hirschmann_rspe32

Required KB Items: Tenable.ot/Hirschmann

Exploit Ease: No known exploits are available

Patch Publication Date: 8/5/2019

Vulnerability Publication Date: 8/5/2019

Reference Information

CVE: CVE-2019-12264

CWE: 88