Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass
Summary
| CVE | CVE-2021-4477 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-03 23:17:01 UTC |
| Updated | 2026-04-03 23:17:01 UTC |
| Description | Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by establishing IPv6 IPsec connections (IKEv1 or IKEv2) while simultaneously using an IPv6 Internet connection to circumvent firewall policy enforcement. |
Risk And Classification
Primary CVSS: v4.0 9.3 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-284 | CWE-284 CWE-284 Improper access control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 3.80-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 8.90-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.00-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.00-RU1 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.10-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU1 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU2 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU3 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU4 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU5 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU6 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU7 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU8 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.12-RU9 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.13-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 9.13-RU1 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 10.12-REL custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | affected 10.12-RU1 custom | Not specified |
| CNA | Belden | Hirschmann HiLCOS OpenBAT | unaffected 10.12-RU2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.vulncheck.com/advisories/hirschmann-hilcos-openbat-bat450-ipv6-ipsec-firewa... | [email protected] | www.vulncheck.com | |
| assets.belden.com/m/5fd1a50fa50cb252/original/Belden-Security-Bulletin-BSECV-1v... | [email protected] | assets.belden.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.