CVE-2017-20237
A security flaw in Hirschmann Industrial HiVision allows attackers to bypass the login process entirely. This allows them to run unauthorized commands on the system without needing a username or password.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03.
Real-world impact
An attacker could gain full administrative control over the system, allowing them to execute arbitrary commands and potentially take over the underlying operating system.
Why this severity
This vulnerability is rated as critical because it requires no user interaction or authentication, allowing a remote attacker to gain full administrative control over the system.
What to do about it
- 01Upgrade Hirschmann Industrial HiVision to version 06.0.07 or 07.0.03 or later.
NVD-referenced vendor advisory
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.