packetstormsecurity.com
http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.html CVE-2022-28172
MEDIUM
Record summary
CVE-2022-28172 has a selected CVSS score of 6.5 (medium).
Description
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024DBrowse hikvision / DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D | CVE List | V2.X to ≤ V2.3.8-6 | affected |
DS-A71024/48R-CVS,DS-A72024/48R-CVSBrowse hikvision / DS-A71024/48R-CVS,DS-A72024/48R-CVS | CVE List | V1.X to ≤ V1.1.4 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28172 hikvision.com
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products