Hima manufactures safety instrumentation and control systems for industrial process applications, with its vulnerability footprint concentrated in a focused line of field communication modules and CPU firmware components. The observed weakness classes center on resource-consumption issues, search-path and origin-validation defects, and incomplete vulnerability characterizations, reflecting typical concerns in embedded safety control devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hima over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4258HIGH In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to gain privileges via a malicious .exe file and gain full acce | Jan 16, 2023 | 7.8 | 26 | NO | NO |
CVE-2024-24781HIGH An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. | Feb 13, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-24782MEDIUM An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN. | Feb 13, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hima.
Media articles that mention a CVE ID that affects a product developed by Hima — matched by CVE ID, not by vendor name.