Hillstone Network Security Update Advisory (CVE-2024-8073)

Overview
 

An update has been released to address vulnerabilities in Hillstone Network. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-8073

  • Hillstone Networks WAF versions: 5.5R6-2.6.7 (inclusive) ~ 5.5R6-2.8.13 (inclusive)

 

 

Resolved Vulnerabilities

 

Vulnerability in Hillstone Networks Web Application Firewall that allows command injection (CVE-2024-8073)

 

 

Vulnerability Patches

The following product-specific Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2024-8073

  • Hillstone Networks WAF version: 5.5R6-2.8.14

 

 

References

[1] CVE-2024-8073 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-8073

[2] Hillstone security-notification

https://www.hillstonenet.com.cn/security-notification/2024/08/21/mlzrld-2/