Junglewise Threat Intelligence

CVE-2022-4987: Hirschmann Industrial HiVision untrusted search path in external applications

CVE-2022-4987 · Severity: high · CVSS 7.3 · Published 2026-04-03

Vendors: Hirschmann.

Executive brief

Hirschmann Industrial HiVision, a network management software used to monitor industrial automation networks, contains a security flaw in how it handles external applications. A local attacker with limited access can trick the system into running a malicious program instead of the intended one. This could allow the attacker to take full control of the system or disrupt industrial operations by gaining elevated administrative privileges.

Technical details

The vulnerability is classified as an Untrusted Search Path (CWE-426) issue within Hirschmann Industrial HiVision. It stems from insufficient path sanitization when the software executes user-configured external applications. A local attacker with low privileges can exploit this by placing a malicious binary in a directory that is searched before the legitimate application's path. If a user or the system triggers the external application, the malicious binary is executed instead. Depending on the service context, this can lead to arbitrary code execution with elevated privileges. The issue is addressed in version 08.1.04 and was also fixed in the 08.2.x branch.

Affected products

  • Hirschmann Industrial HiVision 08.1.03 and earlier versions prior to 08.1.04; 08.2.00

Timeline

  • 2026-04-03: disclosed: Initial disclosure date
  • 2026-04-03: advisory: NVD and VulnCheck advisory published

References

Related threats