CVE-2021-4477 - CVE House
Back to Database
Status published Critical CVE-2021-4477

Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass

Vulnerability Description

Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by establishing IPv6 IPsec connections (IKEv1 or IKEv2) while simultaneously using an IPv6 Internet connection to circumvent firewall policy enforcement.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4477

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Hirschmann HiLCOS OpenBAT
Vulnerable Versions:
3.80-REL, 8.90-REL, 9.00-REL, 9.00-RU1, 9.10-REL, 9.12-REL, 9.12-RU1, 9.12-RU2, 9.12-RU3, 9.12-RU4, 9.12-RU5, 9.12-RU6, 9.12-RU7, 9.12-RU8, 9.12-RU9, 9.13-REL, 9.13-RU1, 10.12-REL, 10.12-RU1, 10.12-RU2

Timeline

Official Publish: April 3rd, 2026
Last Modified: April 6th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)