packetstormsecurity.com
http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.html CVE-2022-28171
HIGH
Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution
Record summary
CVE-2022-28171 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024DBrowse hikvision / DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D | CVE List | V2.X to ≤ V2.3.8-6 | affected |
DS-A71024/48R-CVS,DS-A72024/48R-CVSBrowse hikvision / DS-A71024/48R-CVS,DS-A72024/48R-CVS | CVE List | V1.X to ≤ V1.1.4 | affected |
Proofs of concept
3Catalogued exploits
ExploitDBHikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code ExecutionExploitDB exploitby Thurein SoeNot analyzed1 file
Repository PoCs
GitHubNyaMeeEain/CVE-2022-28171-POCRepository PoCby NyaMeeEainStars: 4Not analyzed3 files
GitHubaengussong/hikvision_probeRepository PoCby aengussongStars: 3Not analyzed7 files
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/173653/Hikvision-Hybrid-SAN-Ds-a71024-SQL-Injection.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28171 hikvision.com
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products