CVE-2017-20237Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-03: 2Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-03: 204-03
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2017-20237: CRITICAL] Critical vulnerability in Hirschmann Industrial HiVision! Versions prior to 06.0.07 and 07.0.03 allow unauthenticated attackers to execute commands with admin privileges. Update now!#cve,CVE-2017-20237,#cybersecurity https://cvefind.com/CVE-2017-20237

    Post summary

    The post highlights CVE‑2017‑20237, a critical vulnerability allowing unauthenticated command execution on Hirschmann Industrial HiVision systems, and urges users to apply the latest updates.

    0000040
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2017-20237: Hirschmann Industrial HiVision A... Industrial networks running unpatched HiVision are sitting ducks—unauthenticated RCE via exposed service interfaces mea... https://zerodaysignal.com/vulnerability/CVE-2017-20237 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reports that unpatched Hirschmann HiVision industrial devices are susceptible to unauthenticated remote code execution through exposed service interfaces, but offers no details on patches, PoC, or active exploitation.

    0000049
    204 followersView on X

Explore more