The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Hikvision
Subscribe
|
Ds-a71024
Subscribe
Ds-a71024 Firmware
Subscribe
Ds-a71048
Subscribe
Ds-a71048 Firmware
Subscribe
Ds-a71048r-cvs
Subscribe
Ds-a71048r-cvs Firmware
Subscribe
Ds-a71072r
Subscribe
Ds-a71072r Firmware
Subscribe
Ds-a72024
Subscribe
Ds-a72024 Firmware
Subscribe
Ds-a72048r-cvs
Subscribe
Ds-a72048r-cvs Firmware
Subscribe
Ds-a72072r
Subscribe
Ds-a72072r Firmware
Subscribe
Ds-a80316s
Subscribe
Ds-a80316s Firmware
Subscribe
Ds-a80624s
Subscribe
Ds-a80624s Firmware
Subscribe
Ds-a81016s
Subscribe
Ds-a81016s Firmware
Subscribe
Ds-a82024d
Subscribe
Ds-a82024d Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
https://www.hikvision.com/content/dam/hikvision/en/support/cybersecyrity/security-advisory/Patch-for-Fixing-Security-Vulnerability-of-Hybrid-SAN-&-Cluster-Storage.zip
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hikvision
Published:
Updated: 2024-09-16T17:03:49.464Z
Reserved: 2022-03-29T00:00:00
Link: CVE-2022-28171
No data.
Status : Modified
Published: 2022-06-27T18:15:09.033
Modified: 2024-11-21T06:56:53.540
Link: CVE-2022-28171
No data.
OpenCVE Enrichment
No data.