Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Belden
Belden hirschmann Industrial Hivision |
|
| Vendors & Products |
Belden
Belden hirschmann Industrial Hivision |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system. | |
| Title | Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-03T21:05:49.713Z
Updated: 2026-04-06T18:02:03.320Z
Reserved: 2026-04-03T19:47:32.576Z
Link: CVE-2017-20237
Updated: 2026-04-06T18:00:55.475Z
Status : Awaiting Analysis
Published: 2026-04-03T21:17:07.103
Modified: 2026-04-07T13:20:55.200
Link: CVE-2017-20237
No data.
ReportizFlow