---
id: CVE-2023-7342
title: Belden HiSecOS Web Server Privilege Escalation
summary: >-
  HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege
  escalation vulnerability that allows authenticated users with operator or
  auditor roles to escalate privileges to the administrator role by sending
  specially craft…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-269
vendor: Belden
product: Hirschmann HiSecOS EAGLE
affected:
  - hirschmann_hisecos_eagle >= 03.4.00 <= 04.1.00
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-04-02T19:15:02.644087Z'
published: '2026-04-02'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:45.278Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-7342'
references:
  - url: >-
      https://assets.belden.com/m/4828b7cf8b652105/original/Microsoft-Word-Belden_Security_Bulletin_BSECV-2021-07_1v0-docx.pdf
    label: Belden Security Bulletins
  - url: >-
      https://www.vulncheck.com/advisories/belden-hisecos-web-server-privilege-escalation
tags:
  - cve.org
epss: 0.00265
epssPercentile: 0.16679
ingestedAt: '2026-10-01T15:48:17.870Z'
---

## Overview

HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw to gain full administrative access to the affected device.

## Affected

- `hirschmann_hisecos_eagle >= 03.4.00 <= 04.1.00`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
