Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03. This vulnerability resides in the master service, allowing unauthenticated remote attackers to execute arbitrary commands with administrative privileges on the underlying operating system. Exploitation involves invoking exposed interface methods over the remote service to bypass authentication and achieve remote code execution.
Impact
Successful exploitation allows for arbitrary command execution on the operating system with administrative rights.
Remediation
Users can update to Hirschmann Industrial HiVision versions 06.0.07 or 07.0.03 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
