← All CVEs

CVE-2023-6895

medium · 6.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.

6.3
CVSS
89.1%
EPSS (exploit prob.)
100th
EPSS percentile
2023-12-17
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
hikvisionintercom_broadcast_system>= 3.0.3, < 4.1.0
hikvisionds-kd-bkall versions
hikvisionds-kd-disall versions
hikvisionds-kd-eall versions
hikvisionds-kd-inall versions
hikvisionds-kd-infoall versions
hikvisionds-kd-kkall versions
hikvisionds-kd-kk/sall versions
hikvisionds-kd-kpall versions
hikvisionds-kd-kp/sall versions
hikvisionds-kd-mall versions
hikvisionds-kd3003-e6all versions
hikvisionds-kd8003ime1(b)all versions
hikvisionds-kd8003ime1(b)/flushall versions
hikvisionds-kd8003ime1(b)/nsall versions
hikvisionds-kd8003ime1(b)/sall versions
hikvisionds-kd8003ime1(b)/surfaceall versions
hikvisionds-kh6220-le1all versions
hikvisionds-kh6320-le1all versions
hikvisionds-kh6320-tde1all versions
hikvisionds-kh6320-te1all versions
hikvisionds-kh6320-wtde1all versions
hikvisionds-kh6320-wte1all versions
hikvisionds-kh6350-wte1all versions
hikvisionds-kh6351-te1all versions
hikvisionds-kh6351-wte1all versions
hikvisionds-kh63le1(b)all versions
hikvisionds-kh8520-wte1all versions
hikvisionds-kh9310-wte1(b)all versions
hikvisionds-kh9510-wte1(b)all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-6895