PatchSiren cyber security CVE debrief
CVE-2016-15058 Belden CVE debrief
CVE-2016-15058 is a credential exposure vulnerability in Hirschmann HiLCOS Classic Platform switches. User passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enabled. Local network attackers can sniff SNMP traffic or extract configuration data to recover plaintext credentials and gain unauthorized administrative access.
- Vendor
- Belden
- Product
- Hirschmann HiLCOS Classic Platform
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-21
Who should care
Organizations using Hirschmann HiLCOS Classic Platform switches, specifically versions prior to 09.0.06 for Classic L2E, L2P, L3E, L3P and prior to 05.3.07 for Classic L2B, should review and update their configurations to prevent credential exposure.
Technical summary
The vulnerability exists in Hirschmann HiLCOS Classic Platform switches due to the synchronization of user passwords with SNMPv1/v2 community strings. When the feature is enabled, passwords are transmitted in plaintext. An attacker with local network access can exploit this by sniffing SNMP traffic or extracting configuration data to obtain plaintext credentials, leading to unauthorized administrative access.
Defensive priority
High
Recommended defensive actions
- Review and update Hirschmann HiLCOS Classic Platform switch configurations to disable password synchronization with SNMPv1/v2 community strings.
- Implement secure SNMP versions, such as SNMPv3, for configuration and monitoring.
- Restrict SNMP access to trusted networks and systems.
- Regularly monitor SNMP traffic and switch configurations for suspicious activity.
- Consider compensating controls, such as network segmentation and access controls, to limit the impact of potential breaches.
Evidence notes
The CVE record was published on 2026-04-03T22:16:24.563Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. References include a security bulletin from Belden and advisories from KB CERT and Vulncheck.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-15058 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-15058
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-15058 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-15058
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://assets.belden.com/m/1d8273c6205dc400/original/Security-Bulletin-Password-Sync-SNMP-v1-v2-BSECV-2016-12.pdf
-
Source reference
Unverified legacy reference
URL: https://www.kb.cert.org/vuls/id/507216
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/hirschmann-hilcos-classic-platform-password-exposure-via-snmp
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.