PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-20233 Belden CVE debrief

CVE-2017-20233 is a medium-severity vulnerability in Hirschmann HiLCOS products, including OpenBAT, BAT450, WLC, and BAT867. The vulnerability allows attackers to bypass configured filter rules and inject or observe multicast and broadcast packets when management IP address filtering is disabled. This issue is caused by a firewall filtering problem that fails to correctly filter IPv4 multicast and broadcast traffic. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM.

Vendor
Belden
Product
Hirschmann HiLCOS OpenBAT, BAT450, WLC
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-21
Advisory published
2026-04-03
Advisory updated
2026-07-21

Who should care

Network administrators and security teams responsible for Hirschmann HiLCOS products should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review and update firewall configurations to ensure proper filtering of IPv4 multicast and broadcast traffic. Additionally, they should verify and apply vendor patches or updates to affected Hirschmann HiLCOS products.

Technical summary

The vulnerability is caused by a firewall filtering issue that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled. Attackers with network access can exploit this vulnerability to bypass configured filter rules and inject or observe multicast and broadcast packets that should have been blocked by the firewall. The affected products are Hirschmann HiLCOS OpenBAT, BAT450, WLC, and BAT867.

Defensive priority

Medium

Recommended defensive actions

  • Verify and apply vendor patches or updates to affected Hirschmann HiLCOS products
  • Enable management IP address filtering to prevent unauthorized access
  • Monitor network traffic for suspicious multicast and broadcast packets
  • Review and update firewall configurations to ensure proper filtering of IPv4 multicast and broadcast traffic
  • Perform a thorough review of network configurations and asset inventory to identify potential exposure
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-03T23:16:59.763Z and last modified on 2026-07-21T07:10:00.117Z. The NVD entry is currently Awaiting Analysis. The vulnerability affects Hirschmann HiLCOS products OpenBAT, BAT450, WLC, and BAT867. The source details are limited, and defenders should verify the affected scope and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T23:16:59.763Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.