The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Hikvision
Subscribe
|
Ds-a71024
Subscribe
Ds-a71024 Firmware
Subscribe
Ds-a71048
Subscribe
Ds-a71048 Firmware
Subscribe
Ds-a71048r-cvs
Subscribe
Ds-a71048r-cvs Firmware
Subscribe
Ds-a71072r
Subscribe
Ds-a71072r Firmware
Subscribe
Ds-a72024
Subscribe
Ds-a72024 Firmware
Subscribe
Ds-a72048r-cvs
Subscribe
Ds-a72048r-cvs Firmware
Subscribe
Ds-a72072r
Subscribe
Ds-a72072r Firmware
Subscribe
Ds-a80316s
Subscribe
Ds-a80316s Firmware
Subscribe
Ds-a80624s
Subscribe
Ds-a80624s Firmware
Subscribe
Ds-a81016s
Subscribe
Ds-a81016s Firmware
Subscribe
Ds-a82024d
Subscribe
Ds-a82024d Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-32626 | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device. |
Fixes
Solution
https://www.hikvision.com/content/dam/hikvision/en/support/cybersecyrity/security-advisory/Patch-for-Fixing-Security-Vulnerability-of-Hybrid-SAN-&-Cluster-Storage.zip
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hikvision
Published:
Updated: 2024-09-17T01:10:46.622Z
Reserved: 2022-03-29T00:00:00
Link: CVE-2022-28172
No data.
Status : Modified
Published: 2022-06-27T18:15:09.103
Modified: 2024-11-21T06:56:53.690
Link: CVE-2022-28172
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD