VulnerabilityModified
CVE-2022-28172
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability.
MEDIUM 6.1EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- hikvision/ds-a71024 firmware · hikvision/ds-a71048 firmware · hikvision/ds-a71072r firmware · hikvision/ds-a80624s firmware · hikvision/ds-a81016s firmware · hikvision/ds-a72024 firmware · hikvision/ds-a72072r firmware · hikvision/ds-a80316s firmware · hikvision/ds-a82024d firmware · hikvision/ds-a71048r-cvs firmware · hikvision/ds-a72048r-cvs firmware
- Source
- hsrc@hikvision.com
References
- http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.htmlThird Party Advisory, VDB Entry
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/Vendor Advisory
- http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.htmlThird Party Advisory, VDB Entry
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.