Showing 2 vulnerabilities on this page for CSMP (Comprehensive Security Management Platform) iSecure Center

Signals CISA KEV Ransomware Nuclei
Hikvision vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Path Traversal: '../filedir'

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025.

CWE-24Oct 22, 2025
CVSS8.3v3.1EPSS1.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

CWE-78Oct 22, 2025
CVSS8.3v3.1EPSS17.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX