CVE-2017-20238
Hirschmann Industrial HiVision Improper Authorization Privilege Escalation
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as the web interface or SNMP browser to modify device configurations despite having restricted permissions.
| CWE | CWE-285 |
| Vendor | belden |
| Product | hirschmann industrial hivision |
| Published | Apr 3, 2026 |
| Last Updated | Apr 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for belden hirschmann industrial hivision
Be the first to know when new high vulnerabilities affecting belden hirschmann industrial hivision are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
Affected Versions
Belden / Hirschmann Industrial HiVision
06.0.00 โค 06.0.05 0 โค 07.00