← All CVEs

CVE-2022-28171

high · 7.5

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

7.5
CVSS
51.6%
EPSS (exploit prob.)
99th
EPSS percentile
2022-06-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-78CWE-77

Affected products

VendorProductAffected versions
hikvisionds-a71024_firmware<= 2.3.8-6
hikvisionds-a71024all versions
hikvisionds-a71048_firmware<= 2.3.8-6
hikvisionds-a71048all versions
hikvisionds-a71072r_firmware<= 2.3.8-6
hikvisionds-a71072rall versions
hikvisionds-a80624s_firmware<= 2.3.8-6
hikvisionds-a80624sall versions
hikvisionds-a81016s_firmware<= 2.3.8-6
hikvisionds-a81016sall versions
hikvisionds-a72024_firmware<= 2.3.8-6
hikvisionds-a72024all versions
hikvisionds-a72072r_firmware<= 2.3.8-6
hikvisionds-a72072rall versions
hikvisionds-a80316s_firmware<= 2.3.8-6
hikvisionds-a80316sall versions
hikvisionds-a82024d_firmware<= 2.3.8-6
hikvisionds-a82024dall versions
hikvisionds-a71024_firmware<= 1.1.4
hikvisionds-a71024all versions
hikvisionds-a71048r-cvs_firmware<= 1.1.4
hikvisionds-a71048r-cvsall versions
hikvisionds-a72024_firmware<= 1.1.4
hikvisionds-a72024all versions
hikvisionds-a72048r-cvs_firmware<= 1.1.4
hikvisionds-a72048r-cvsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-28171