CVE-2023-7343
HIGHBelden Industrial HiVision Arbitrary Code Execution via Malicious Project File
Title source: cnaDescription
Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an administrator opens a maliciously crafted project file. Successful exploitation allows the attacker to execute code in the context of the HiVision process.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
Belden Security Bulletins
https://assets.belden.com/m/774e2db2b0100bc1/original/Belden-Security-Bulletin-BSECV-2023-06.pdf
Scores
CVSS v3
7.8
EPSS
0.0014
EPSS Percentile
3.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (3)
Belden/Hirschmann Industrial HiVision
05.0.00 - 08.3.01
Belden/Hirschmann Industrial HiVision
08.3.02
Belden/Hirschmann Industrial HiVision
08.3.02 - 04.1.00
Published
Apr 02, 2026
Tracked Since
Apr 03, 2026