CVE-2017-20237 describes a critical authentication bypass vulnerability in Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03. This flaw allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges on the underlying operating system. Rated with a CVSS v3.1 score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low complexity, requiring no user interaction or prior authentication. Despite being on a "Hot List," there is currently no evidence of active exploitation in the wild, and public exploit code is not available on common platforms like Metasploit or ExploitDB. Community discussion regarding this CVE remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Belden | Hirschmann Industrial HiVision | >= 0, <= 06.0.06, >= 0, <= 07.0.02CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.