There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
History

Tue, 22 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision hikcentral Master
Weaknesses CWE-1236
CPEs cpe:2.3:a:hikvision:hikcentral_master:*:*:*:*:lite:*:*:*
Vendors & Products Hikvision hikcentral Master
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision hikcentral Master Lite
CPEs cpe:2.3:a:hikvision:hikcentral_master_lite:2.0.0:*:*:*:*:*:*:*
Vendors & Products Hikvision
Hikvision hikcentral Master Lite
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Oct 2024 08:45:00 +0000

Type Values Removed Values Added
Description There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published: 2024-10-18T08:29:38.392Z

Updated: 2024-10-18T13:45:44.086Z

Reserved: 2024-09-25T06:22:37.960Z

Link: CVE-2024-47485

cve-icon Vulnrichment

Updated: 2024-10-18T13:45:38.943Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-18T09:15:03.093

Modified: 2024-10-22T16:23:22.890

Link: CVE-2024-47485

cve-icon Redhat

No data.