Record summary

CVE-2024-29949 has a selected CVSS score of 7.2 (high).

Description

There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 16
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListV4.30.096build221220 and the versions prior to itaffected
Through V4.30.096build221220affected

Default status: unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.01.070(not including V5.01.070)affected
5.00.000 to < 5.01.070affected

Default status: unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
V5.00.000 to < V5.02.006affected
CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected

Default status: affected, unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
5.00.000 to < 5.02.006affected
CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected

Default status: unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
5.00.000 to < 5.02.006affected

Default status: unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
5.00.000 to < 5.02.006affected

Default status: unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
5.00.000 to < 5.02.006affected

Default status: unknown

CVE ListVersions after V5.00.000 (including V5.00.000) and before V5.02.006(not including V5.02.006)affected
5.00.000 to < 5.02.006affected

References

2