Vulnerability CVE-2022-28171


Published: 2022-06-27

Description:
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Hikvision Remote Code Execution / XSS / SQL Injection
Thurein Soe
02.02.2023
High
Hikvision Hybrid SAN Ds-a71024 Firmware Multiple Remote Code Execution
Thurein Soe
19.07.2023
Med.
Hikvision Hybrid SAN Ds-a71024 SQL Injection
Thurein Soe
21.07.2023

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/

Copyright 2024, cxsecurity.com

 

Back to Top