Path Hijacking Vulnerability in Hirschmann Industrial HiVision Software
CVE-2022-4987
What is CVE-2022-4987?
The Hirschmann Industrial HiVision software versions prior to 08.1.04 and 08.2.00 are susceptible to a vulnerability that enables local attackers to execute arbitrary binaries. This weakness arises from inadequate path sanitization in the execution of user-configured external applications. An attacker could exploit this vulnerability by placing a malicious binary within the execution path of an external application. When triggered, this could lead to the execution of unauthorized code with elevated privileges, contingent upon the privileges of the affected application. Timely updates are essential to mitigate potential threats.
Affected Version(s)
Hirschmann Industrial HiVision 0 <= 08.1.03
Hirschmann Industrial HiVision 0 <= 08.1.03
Hirschmann Industrial HiVision 08.1.04
