CVE-2017-20237
Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.3EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
03 abr 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Belden · Hirschmann Industrial HiVision¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →