CVE-2024-14033

HIGH

Hirschmann EagleSDV Denial of Service via TLS

Title source: cna
STIX 2.1

Description

Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device during TLS handshake by exploiting protocol downgrades to TLS 1.0 or TLS 1.1, interrupting service availability.

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 34.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
Belden/Hirschmann EagleSDV < 05.4.01
Belden/Hirschmann EagleSDV 05.4.02
Published Apr 02, 2026
Tracked Since Apr 03, 2026