<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>HiOS Switch Platform (&lt; 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, 10.5.00) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hios-switch-platform--07.1.12-08.7.10-09.0.13-09.3.03-10.3.08-10.5.00/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 15:41:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hios-switch-platform--07.1.12-08.7.10-09.0.13-09.3.03-10.3.08-10.5.00/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform</title><link>https://feed.craftedsignal.io/briefs/2026-09-hirschmann-dos/</link><pubDate>Tue, 15 Sep 2026 15:41:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-hirschmann-dos/</guid><description>Hirschmann HiOS Switch Platform devices are susceptible to a remote unauthenticated denial-of-service vulnerability due to improper input validation in the integrated web server.</description><content:encoded><![CDATA[<p>Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in their integrated web server. The flaw arises from missing validation of HTTP(S) content processed by the device. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP(S) request to a specific endpoint, which triggers an unintended reboot of the switch. This results in a temporary denial-of-service condition for the device and any traffic passing through it. The vulnerability is tracked as CVE-2026-89025. Hirschmann has released security updates to address this issue, and administrators are advised to verify firmware versions against the patched releases.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in an immediate and temporary denial-of-service of Hirschmann network switches, which can disrupt critical infrastructure communication. Affected sectors include industrial control systems and enterprise network environments where HiOS-based switches are deployed to manage traffic. Impact is limited to device availability due to forced reboots.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade affected Hirschmann HiOS firmware to the patched versions: 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00.</li>
<li>Restrict access to the management web interface of network switches to trusted management subnets or via out-of-band management networks to minimize the attack surface for CVE-2026-89025.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>