CVE-2023-7343 PUBLISHED

Belden Industrial HiVision Arbitrary Code Execution via Malicious Project File

Assigner: VulnCheck
Reserved: 01.04.2026 Published: 02.04.2026 Updated: 02.04.2026

HiSecOS web server versions 05.0.00 to 08.3.01 prior to 08.3.02 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw to gain full administrative access to the affected device.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Belden
Product Hirschmann Industrial HiVision
Versions Default: unaffected
  • unaffected from 08.3.02 to 04.1.00 (incl.)
  • affected from 05.0.00 to 08.3.01 (incl.)

References

Problem Types

  • CWE-269 Improper Privilege Management CWE