A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Hikvision
Subscribe
|
Ds-kd-bk
Subscribe
Ds-kd-dis
Subscribe
Ds-kd-e
Subscribe
Ds-kd-in
Subscribe
Ds-kd-info
Subscribe
Ds-kd-kk
Subscribe
Ds-kd-kk\/s
Subscribe
Ds-kd-kp
Subscribe
Ds-kd-kp\/s
Subscribe
Ds-kd-m
Subscribe
Ds-kd3003-e6
Subscribe
Ds-kd8003ime1\(b\)
Subscribe
Ds-kd8003ime1\(b\)\/flush
Subscribe
Ds-kd8003ime1\(b\)\/ns
Subscribe
Ds-kd8003ime1\(b\)\/s
Subscribe
Ds-kd8003ime1\(b\)\/surface
Subscribe
Ds-kh6220-le1
Subscribe
Ds-kh6320-le1
Subscribe
Ds-kh6320-tde1
Subscribe
Ds-kh6320-te1
Subscribe
Ds-kh6320-wtde1
Subscribe
Ds-kh6320-wte1
Subscribe
Ds-kh6350-wte1
Subscribe
Ds-kh6351-te1
Subscribe
Ds-kh6351-wte1
Subscribe
Ds-kh63le1\(b\)
Subscribe
Ds-kh8520-wte1
Subscribe
Ds-kh9310-wte1\(b\)
Subscribe
Ds-kh9510-wte1\(b\)
Subscribe
Intercom Broadcast System
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 21 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-11-21T14:28:13.968Z
Reserved: 2023-12-16T15:16:15.629Z
Link: CVE-2023-6895
Updated: 2024-08-02T08:42:08.393Z
Status : Modified
Published: 2023-12-17T08:15:07.173
Modified: 2024-11-21T08:44:46.973
Link: CVE-2023-6895
No data.
OpenCVE Enrichment
No data.
Weaknesses