CVE-2017-20238
Last modified
CVE-2017-20238 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as the web interface or SNMP browser to modify device configurations despite having restricted permissions.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as the web interface or SNMP browser to modify device configurations despite having restricted permissions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Belden | Hirschmann Industrial HiVision | >= 06.0.00, <= 06.0.05; <= 07.00 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2017-20238?
How severe is CVE-2017-20238?
How do I fix CVE-2017-20238?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflow.…10
- CVE-2017-20233Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 cont…5.4
- CVE-2017-20234GarrettCom Magnum 6K and 10K managed switches contain an aut…9.8
- CVE-2017-20235ProSoft Technology ICX35-HWC version 1.3 and prior cellular …9.8
- CVE-2017-20236ProSoft Technology ICX35-HWC versions 1.3 and prior cellular…9.8
- CVE-2017-20237Hirschmann Industrial HiVision versions prior to 06.0.07 and…9.8
- CVE-2017-20239MDwiki contains a cross-site scripting vulnerability that al…6.1
- CVE-2017-2024Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-20240Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerab…5.9
- CVE-2017-20241Keysight IxChariot Endpoint before 9.5.102 contains a heap-b…9.8
- CVE-2017-20242Keysight IxChariot Endpoint before 9.5.102 contains a stack-…9.8
- CVE-2017-20243WordPress Car Park Booking Plugin version 13 October 17 cont…8.8
Are you affected by CVE-2017-20238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
