CVE-2016-15058
Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enabled. Attackers with local network access can sniff SNMP traffic or extract configuration data to recover plaintext credentials and gain unauthorized administrative access to the switches.
| CWE | CWE-257 |
| Vendor | belden |
| Product | hirschmann hilcos classic platform |
| Published | Apr 3, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for belden hirschmann hilcos classic platform
Be the first to know when new high vulnerabilities affecting belden hirschmann hilcos classic platform are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Belden / Hirschmann HiLCOS Classic Platform
0 โค 09.0.05 0 โค 05.3.06