Showing 3 vulnerabilities on this page for DS-A71024/48R-CVS,DS-A72024/48R-CVS

Signals CISA KEV Ransomware Nuclei
Hikvision vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

CWE-284Apr 11, 2023
CVSS9.1v3.1EPSS0.825%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.

CWE-79Jun 27, 2022
CVSS6.5v3.1EPSS0.763%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

CWE-77CWE-78Jun 27, 2022
CVSS7.5v3.1EPSS49.9%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX