CVE-2022-4987: Hirschmann Industrial HiVision External Application Path Hijacking Leading to Arbitrary Code Execution
Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker to execute arbitrary binaries. Due to insufficient path sanitization, an attacker can place a malicious binary in the execution path of a configured external application, causing it to be executed instead of the intended application. This can result in execution with elevated privileges depending on the context of the external application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann Industrial HiVisionto a version that resolves this vulnerability.Fixed in 08.1.04 - Upgrade
Upgrade
Hirschmann Industrial HiVisionto a version that resolves this vulnerability.Fixed in 08.2.00
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4987?
CVE-2022-4987 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2022-4987?
To fix CVE-2022-4987, upgrade Hirschmann Industrial HiVision to version 08.1.04 or later.
What type of attack does CVE-2022-4987 enable?
CVE-2022-4987 enables local attackers to execute arbitrary code through hijacking of user-configured external applications.
Which versions of Hirschmann Industrial HiVision are affected by CVE-2022-4987?
CVE-2022-4987 affects Hirschmann Industrial HiVision versions prior to 08.1.04 and version 08.2.00.
Who is impacted by CVE-2022-4987?
Organizations using vulnerable versions of Hirschmann Industrial HiVision are impacted by CVE-2022-4987.