---
id: CVE-2017-20233
title: >-
  Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall
  filtering vulnerability that fails to correctly filter IPv4 multicast and
  broadcast traffic when management IP address filtering is disabled, allowing
  configured…
summary: >-
  Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall
  filtering vulnerability that fails to correctly filter IPv4 multicast and
  broadcast traffic when management IP address filtering is disabled, allowing
  configured…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-284
published: '2026-04-03'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-20233'
references:
  - url: >-
      https://assets.belden.com/m/11a07596f0bf1018/original/Security-Bulletin-IPv4-Multicast-HiLCOS-Layer-2-Firewall-BSECV-2017-03.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hirschmann-hilcos-layer-2-firewall-multicast-broadcast-traffic-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00204
epssPercentile: 0.10644
ingestedAt: '2026-07-21T16:51:40.763Z'
---

## Overview

Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can inject or observe multicast and broadcast packets that should have been blocked by the firewall.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
