Ad

CVE-2017-20238

HIGH CVSS 4.0: 7.1 EPSS 0.00%
Updated Apr 03, 2026
Hirschmann Industrial
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 06.0.06
Type CWE-285 (Improper Authorization)
Vendor Hirschmann Industrial
Public PoC No

Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as the web interface or SNMP browser to modify device configurations despite having restricted permissions.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0