CVE-2023-6895
Hikvision Intercom Broadcasting System ping.php os command injection
Record summary
CVE-2023-6895 has a selected CVSS score of 6.3 (medium); EIP currently links 2 repository PoCs and 1 Nuclei template.
Description
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Intercom Broadcasting SystemBrowse Hikvision / Intercom Broadcasting System | CVE List | 3.0.3_20201113_RELEASE(HIK) | affected |
intercom_broadcast_systemBrowse Hikvision / intercom_broadcast_system | VulnCheck | Version data not supplied | |
Proofs of concept
2Repository PoCs
GitHubFuBoLuSec/CVE-2023-6895Repository PoCby FuBoLuSecStars: 1Not analyzed2 files
GitHubnles-crt/CVE-2023-6895Repository PoCby nles-crtStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALHikvision IP ping.php - Command ExecutionCVSS 9.8
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.
Impact
Unauthenticated attackers can execute arbitrary operating system commands via the jsondata[ip] parameter, potentially gaining complete control over the Hikvision Intercom Broadcasting System.
Remediation
Upgrade to Hikvision Intercom Broadcasting System version 4.1.0 or later.
Source: ProjectDiscovery