PT-2026-30210 · Belden · Hirschmann Industrial Hivision
CVE-2022-4987
·
Published
2026-04-03
·
Updated
2026-07-24
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hirschmann Industrial HiVision versions 08.1.03 through 08.1.03
Hirschmann Industrial HiVision version 08.2.00
Description
Insufficient path sanitization during the execution of user-configured external applications allows a local attacker to execute arbitrary binaries. By placing a malicious binary in the execution path of a configured external application, the attacker can ensure their binary is executed instead of the intended one, potentially resulting in execution with elevated privileges.
Recommendations
Update Hirschmann Industrial HiVision version 08.1.03 to version 08.1.04.
Update Hirschmann Industrial HiVision version 08.2.00 to a newer version containing the fix.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hirschmann Industrial Hivision