vendor:
Hikvision Hybrid SAN Ds-a71024 Firmware
by:
Thurein Soe
9.8
CVSS
CRITICAL
Remote Code Execution
89
CWE
Product Name: Hikvision Hybrid SAN Ds-a71024 Firmware
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2022-28171
CPE:
Platforms Tested:
2023
Hikvision Hybrid SAN Ds-a71024 Firmware – Multiple Remote Code Execution
Some Hikvision Hybrid SAN products were vulnerable to multiple remote code execution vulnerabilities such as command injection, Blind SQL injection, HTTP request smuggling, and reflected cross-site scripting. This resulted in remote code execution that allows an adversary to execute arbitrary operating system commands and more. However, an adversary must be on the same network to leverage this vulnerability to execute arbitrary commands.
Mitigation:
Unknown