{"id":"CVE-2023-53908","title":"HiSecOS 04.0.01 Privilege Escalation via User Role Modification","summary":"HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-269"],"vendor":"Belden","product":"HiSecOS","affected":["HiSecOS 04.0.01"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2025-12-18T14:51:21.277692Z"},"published":"2025-12-17","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:19:42.647Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2023-53908","references":[{"url":"https://www.exploit-db.com/exploits/51537","label":"ExploitDB-51537"},{"url":"https://www.belden.com/products/industrial-networking-cybersecurity/software-solutions/device-software/hisecos-firewall-software","label":"Official Product Webpage"},{"url":"https://www.vulncheck.com/advisories/hisecos-privilege-escalation-via-user-role-modification","label":"VulnCheck Advisory: HiSecOS 04.0.01 Privilege Escalation via User Role Modification"}],"tags":["cve.org"],"epss":0.00342,"epssPercentile":0.25343,"ingestedAt":"2026-10-01T15:48:17.871Z","slug":"CVE-2023-53908","body":"## Overview\n\nHiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.\n\n## Affected\n\n- `HiSecOS 04.0.01`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}