Record summary

CVE-2022-28172 has a selected CVSS score of 6.5 (medium).

Description

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D

Browse hikvision / DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D
CVE ListV2.X to ≤ V2.3.8-6affected
CVE ListV1.X to ≤ V1.1.4affected

References

3