Podatność CVE-2022-28171


Publikacja: 2022-06-27

Opis:
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
Med.
Hikvision Remote Code Execution / XSS / SQL Injection
Thurein Soe
02.02.2023
High
Hikvision Hybrid SAN Ds-a71024 Firmware Multiple Remote Code Execution
Thurein Soe
19.07.2023
Med.
Hikvision Hybrid SAN Ds-a71024 SQL Injection
Thurein Soe
21.07.2023

Typ:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 Referencje:
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/

Copyright 2024, cxsecurity.com

 

Back to Top