CVE-2017-20233
Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 mult
CVSS
5.4
Medio
EPSS
0.2%
p11
KEV
—
Exploit Today
3
0-100
Publicado: 3 abr 2026 · Última mod.: 21 jul 2026 · CWE-284
0.2%EPSS · 30 días0.2%
2026-07-152026-08-12
Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can inject or observe multicast and broadcast packets that should have been blocked by the firewall.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-595058.6 ALT—
——0CWE-284: Improper Access Control6hCVE-2026-595018.2 ALT—
——0CWE-284: Improper Access Control6hCVE-2026-133677.8 ALT—
——0IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.19hCVE-2026-599177.8 ALT—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.11hCVE-2026-599147.8 ALT—
——0Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.11hCVE-2026-67287——
——0Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.1d