CVE-2024-14034Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication handling to obtain elevated privileges and perform unauthorized actions including configuration download or upload and firmware modification.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-02); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-02: 3Mentions · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-02: 1Technical Details · 2026-04-02: 3Technical Details · 2026-04-03: 104-0204-03
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-023
Disclosure2General1
2026-04-031
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2024-14034 Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote … https://www.cve.org/CVERecord?id=CVE-2024-14034

    Post summary

    CVE‑2024‑14034 is an authentication bypass flaw in HiEOS devices (versions before 01.1.00) that allows unauthenticated remote access via the HTTP(S) management module.

    00000120
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2024-14034: CRITICAL] Beware: Hirschmann HiEOS devices have a critical authentication bypass vulnerability. Attackers can gain admin access remotely by sending crafted requests, leading to unauthorized ...#cve,CVE-2024-14034,#cybersecurity https://cvefind.com/CVE-2024-14034

    Post summary

    CVE-2024-14034 exposes a critical authentication bypass on Hirschmann HiEOS devices, enabling attackers to gain remote admin access through crafted requests, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000059
    617 followersView on X
  • Galdino XS@galdinociber
    Disclosure

    CVE-2024-14034: authentication bypass nos dispositivos Hirschmann HiEOS, CVSS 9.8. Um atacante remoto sem credenciais consegue acesso administrativo completo via HTTP(S) com requests especialmente construídos.

    Post summary

    CVE‑2024‑14034 is an authentication bypass flaw in Hirschmann HiEOS devices that allows remote attackers to obtain full admin access through crafted HTTP(S) requests. No exploit code, patch, or evidence of active exploitation is mentioned.

    0000040
    1 followersView on X
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2024-14034: Hirschmann HiEOS Authentication ... Remote admin takeover on industrial switches via malformed HTTP requests - perfect OT pivot point for APTs targeting cr... https://zerodaysignal.com/vulnerability/CVE-2024-14034 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts to CVE-2024-14034, describing a remote admin takeover via malformed HTTP requests on Hirschmann HiEOS switches, highlighting its potential as an OT pivot point for APTs without indicating confirmed exploitation, patch, or PoC details.

    0000061
    193 followersView on X

Explore more