Impact
The vulnerability is caused by insufficient validation of input parameters in the firmware of certain Hikvision camera models, allowing unauthenticated attackers to retrieve partial sensitive data. The flaw corresponds to CWE-20 and results in a confidentiality breach.
Affected Systems
The flaw affects Hikvision DS-2CD Series, DS-2DE Series, DS-2DP Series, and DS-2TD Series cameras. No specific firmware versions are identified in the advisory; any device running the affected firmware should be considered at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% reflects a low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw allows unauthenticated attackers to supply crafted input to the camera’s firmware, suggesting that the attack requires remote network reachability to the affected interfaces. (Inferred from the advisory indicating unauthenticated access) Exploitation would involve sending the malformed request to trigger the data disclosure.
OpenCVE Enrichment