CVE-2024-47485

CRITICAL

HikCentral Master Lite - Code Injection

Title source: llm
STIX 2.1

Description

There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.

Scores

CVSS v3 9.8
EPSS 0.0081
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1236
Status published
Products (1)
hikvision/hikcentral_master 2.0.0 - 2.3.0
Published Oct 18, 2024
Tracked Since Feb 18, 2026