CVE-2023-7343: Belden Industrial HiVision Arbitrary Code Execution via Malicious Project File
Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an administrator opens a maliciously crafted project file. Successful exploitation allows the attacker to execute code in the context of the HiVision process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann Industrial HiVisionto a version that resolves this vulnerability.Fixed in 08.3.02
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7343?
CVE-2023-7343 is rated as a high severity vulnerability due to its ability to allow privilege escalation in affected software.
How do I fix CVE-2023-7343?
To fix CVE-2023-7343, upgrade your Belden Industrial HiVision or HiSecOS web server to version 08.3.02 or later.
Who is affected by CVE-2023-7343?
Users with operator or auditor roles in Belden Industrial HiVision and HiSecOS web server versions 05.0.00 to 08.3.01 are affected by CVE-2023-7343.
What type of vulnerability is CVE-2023-7343?
CVE-2023-7343 is an arbitrary code execution vulnerability that enables authenticated users to escalate their privileges.
What are the potential consequences of CVE-2023-7343?
The potential consequences of CVE-2023-7343 include unauthorized access to administrative functions and the ability to execute arbitrary code on the system.