Impact
An arbitrary code execution flaw exists in Hirschmann Industrial HiVision firmware versions 05.0.00 through 08.3.01. The vulnerability manifests when an administrator opens a maliciously crafted project file. If exploited, the attacker can execute arbitrary code within the context of the HiVision process, effectively gaining administrative privileges on the device. The primary weakness arises from improper validation of the project file format, categorized as CWE-269 (Improper Privilege Management).
Affected Systems
Devices running Belden Hirschmann Industrial HiVision firmware versions 05.0.00 to 08.3.01 are impacted. The issue is resolved in firmware 08.3.02 and later. Users should identify devices with affected firmware and plan an upgrade.
Risk and Exploitability
The CVSS score of 8.5 signals a high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an administrator obtain and open a maliciously crafted project file; thus, the attack vector is local or delegated access rather than remote. Successful exploitation would enable an attacker to run code as the HiVision process, potentially leading to full control of the device.
OpenCVE Enrichment