Junglewise Threat Intelligence

CVE-2023-7343: Hirschmann Industrial HiVision arbitrary code execution in project files

CVE-2023-7343 · Severity: high · CVSS 7.8 · Published 2026-04-02

Vendors: Hirschmann.

Executive brief

Hirschmann Industrial HiVision, a network management software for industrial automation, is vulnerable to a security flaw that could allow an attacker to take control of the system. This occurs when an administrator is tricked into opening a specially crafted project file. If exploited, an attacker could execute malicious commands, potentially leading to unauthorized access to industrial network configurations or operational disruptions.

Technical details

An arbitrary code execution vulnerability exists in Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01. The flaw is triggered during the processing of project files; if a user with administrative privileges opens a specially crafted file, the application fails to properly validate the contents, leading to code execution within the context of the HiVision process. This is a local attack vector requiring user interaction (UI:R). The vulnerability is addressed in version 08.3.02. Note: Some advisory sources also mention a related privilege escalation path via crafted packets to the HiSecOS web server component.

Affected products

  • Hirschmann Industrial HiVision 05.0.00 through 08.3.01

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats