Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03. This vulnerability resides in the master service, allowing unauthenticated remote attackers to execute arbitrary commands with administrative privileges on the underlying operating system. Exploitation involves invoking exposed interface methods over the remote service to bypass authentication and achieve remote code execution.

Impact

Successful exploitation allows for arbitrary command execution on the operating system with administrative rights.

Remediation

Users can update to Hirschmann Industrial HiVision versions 06.0.07 or 07.0.03 to address this vulnerability.

Added: Apr 3, 2026, 9:31 PM
Updated: Apr 3, 2026, 9:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
5.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.