Record summary

CVE-2022-28171 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Affected products and versions

2
ProductSourceVersion rangeStatus

DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D

Browse hikvision / DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D
CVE ListV2.X to ≤ V2.3.8-6affected
CVE ListV1.X to ≤ V1.1.4affected

Proofs of concept

3

Catalogued exploits

ExploitDBHikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code ExecutionExploitDB exploitby Thurein SoeNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubNyaMeeEain/CVE-2022-28171-POCRepository PoCby NyaMeeEainStars: 4Not analyzed3 files

5.4 KiB

GitHub

PoC details
GitHubaengussong/hikvision_probeRepository PoCby aengussongStars: 3Not analyzed7 files

7.6 KiB · linked to 3 vulnerabilities

GitHub

PoC details

References

4