CVE-2022-4987
7.3Belden · Hirschmann Industrial HiVision
A vulnerability in Hirschmann Industrial HiVision allows local attackers to execute arbitrary binaries via untrusted search path hijacking.
Executive summary
A local path traversal vulnerability in Belden Hirschmann Industrial HiVision allows attackers to execute arbitrary code with elevated privileges.
Vulnerability
This flaw involves an untrusted search path (CWE-426) where insufficient path sanitization allows a local, authenticated attacker to place malicious binaries in the execution path of configured external applications.
Business impact
Successful exploitation allows a local attacker to execute arbitrary code, potentially leading to full system compromise or privilege escalation. With a CVSS score of 7.3, this represents a significant risk to industrial control environments, as the integrity and availability of the affected management software are critical to operational continuity.
Remediation
Immediate Action: Update to Hirschmann Industrial HiVision version 08.1.04, 08.2.00, or later to resolve the search path vulnerability.
Proactive Monitoring: Audit system logs for unexpected execution of binaries or unauthorized changes to file paths configured for external applications.
Compensating Controls: Restrict local system access to authorized personnel and ensure that directories used for external application configurations have strictly enforced access control lists.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
The vulnerability poses a substantial risk to systems running Hirschmann Industrial HiVision by enabling local code execution. Organizations should prioritize updating their software to the fixed versions specified by Belden to eliminate the insecure search path. Until updates are deployed, strict adherence to the principle of least privilege for local system users is essential to prevent unauthorized binary placement.