VulnerabilityModified
CVE-2022-28171
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability.
CRITICAL 9.8EPSS 52.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 52.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 52.06% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78, CWE-77
- Affected
- hikvision/ds-a71024 firmware · hikvision/ds-a71048 firmware · hikvision/ds-a71072r firmware · hikvision/ds-a80624s firmware · hikvision/ds-a81016s firmware · hikvision/ds-a72024 firmware · hikvision/ds-a72072r firmware · hikvision/ds-a80316s firmware · hikvision/ds-a82024d firmware · hikvision/ds-a71048r-cvs firmware · hikvision/ds-a72048r-cvs firmware
- Source
- hsrc@hikvision.com
References
- http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/173653/Hikvision-Hybrid-SAN-Ds-a71024-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/Vendor Advisory
- http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/173653/Hikvision-Hybrid-SAN-Ds-a71024-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.