SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-28171

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability.

CRITICAL 9.8EPSS 52.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 52.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
52.06% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-78, CWE-77
Affected
hikvision/ds-a71024 firmware · hikvision/ds-a71048 firmware · hikvision/ds-a71072r firmware · hikvision/ds-a80624s firmware · hikvision/ds-a81016s firmware · hikvision/ds-a72024 firmware · hikvision/ds-a72072r firmware · hikvision/ds-a80316s firmware · hikvision/ds-a82024d firmware · hikvision/ds-a71048r-cvs firmware · hikvision/ds-a72048r-cvs firmware
Source
hsrc@hikvision.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.