CVE-2023-7343

HIGH

Belden Industrial HiVision Arbitrary Code Execution via Malicious Project File

Title source: cna
STIX 2.1

Description

Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an administrator opens a maliciously crafted project file. Successful exploitation allows the attacker to execute code in the context of the HiVision process.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (3)
Belden/Hirschmann Industrial HiVision 05.0.00 - 08.3.01
Belden/Hirschmann Industrial HiVision 08.3.02
Belden/Hirschmann Industrial HiVision 08.3.02 - 04.1.00
Published Apr 02, 2026
Tracked Since Apr 03, 2026