CVE-2022-4986 Details
Description
Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.
A denial-of-service vulnerability has been identified in Hirschmann EagleSDV devices. The issue arises when the device crashes during the establishment of TLS sessions using versions 1.0 or 1.1. Attackers can exploit this vulnerability by initiating TLS connections with these protocol versions, leading to a disruption in service availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://assets.belden.com/m/1c8fe5d916567af6/original/Belden_Security_Bulletin_BSECV-2022-08.pdf | [email protected] | Third Party Advisory |
| https://www.vulncheck.com/advisories/hirschmann-eaglesdv-denial-of-service-via-tls | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| beldan eaglesdv firmware | < 05.4.02 |
CPE
Remediation
| |
| beldan eaglesdv | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | New CVE Received | [email protected] |