CVE-2017-20238 HIGH

CVE-2017-20238: Hirschmann Industrial HiVision Improper Authorization Privilege Escalation

Vendor Belden
Product Hirschmann Industrial HiVision
Weakness CWE-285
Published April 3, 2026
Last update May 25, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

What the vulnerability does

01Description

Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as the web interface or SNMP browser to modify device configurations despite having restricted permissions.

Key dates

02Disclosure timeline

April 3, 2026 CVE published
May 25, 2026 Record updated

Related vulnerabilities

04Related CVE