Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as the web interface or SNMP browser to modify device configurations despite having restricted permissions.
References
Configurations
No configuration.
History
03 Apr 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-03 23:17
Updated : 2026-04-07 13:20
NVD link : CVE-2017-20238
Mitre link : CVE-2017-20238
CVE.ORG link : CVE-2017-20238
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
