Description
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.
Published: 2022-06-27
Score: 7.5 High
EPSS: 84.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

https://www.hikvision.com/content/dam/hikvision/en/support/cybersecyrity/security-advisory/Patch-for-Fixing-Security-Vulnerability-of-Hybrid-SAN-&-Cluster-Storage.zip

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.85026}

epss

{'score': 0.85968}


Subscriptions

Hikvision Ds-a71024 Ds-a71024 Firmware Ds-a71048 Ds-a71048 Firmware Ds-a71048r-cvs Ds-a71048r-cvs Firmware Ds-a71072r Ds-a71072r Firmware Ds-a72024 Ds-a72024 Firmware Ds-a72048r-cvs Ds-a72048r-cvs Firmware Ds-a72072r Ds-a72072r Firmware Ds-a80316s Ds-a80316s Firmware Ds-a80624s Ds-a80624s Firmware Ds-a81016s Ds-a81016s Firmware Ds-a82024d Ds-a82024d Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published:

Updated: 2024-09-16T17:03:49.464Z

Reserved: 2022-03-29T00:00:00.000Z

Link: CVE-2022-28171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-27T18:15:09.033

Modified: 2024-11-21T06:56:53.540

Link: CVE-2022-28171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses