PT-2026-30246 · Undefined · Undefined
CVE-2016-15058
·
Published
2026-04-03
·
Updated
2026-07-21
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Hirschmann HiLCOS Classic Platform Classic L2E, L2P, L3E, L3P versions prior to 09.0.06
Hirschmann HiLCOS Classic Platform Classic L2B versions prior to 05.3.07
Description
A credential exposure issue exists where user passwords are synchronized with SNMPv1/v2 community strings. When this feature is enabled, passwords are transmitted in plaintext. Attackers with local network access can intercept SNMP traffic or extract configuration data to recover these plaintext credentials and gain unauthorized administrative access to the switches.
Recommendations
Update Classic L2E, L2P, L3E, and L3P to version 09.0.06 or later.
Update Classic L2B to version 05.3.07 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined