CVE-2016-15058 - CVE House
Back to Database
Status published High CVE-2016-15058

Hirschmann HiLCOS Classic Platform Password Exposure via SNMP

Vulnerability Description

Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enabled. Attackers with local network access can sniff SNMP traffic or extract configuration data to recover plaintext credentials and gain unauthorized administrative access to the switches.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-15058

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Hirschmann HiLCOS Classic Platform
Vulnerable Versions:
>= 09.0.06, >= 05.3.07, 0

Timeline

Official Publish: April 3rd, 2026
Last Modified: May 14th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.