CVE-2022-28171

Scores

EPSS

0.841high84.1%
0%20%40%60%80%100%

Percentile: 84.1%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-78

Exploits

Exploit ID: 51607

Source: exploitdb

URL: https://www.exploit-db.com/exploits/51607

Exploit ID: CVE-2022-28171

Source: github-poc

URL: https://github.com/NyaMeeEain/CVE-2022-28171-POC

Vulnerable Software (13)

Type: Configuration

Vendor: *

Product: ds-a71024_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a71024_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerable...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a71024_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a71024_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "1.1.4",          "vulnerable":...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a71048_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a71048_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerable...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a71048r-cvs_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a71048r-cvs_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "1.1.4",          "vulnera...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a71072r_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a71072r_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerabl...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a72024_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a72024_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerable...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a72024_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a72024_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "1.1.4",          "vulnerable":...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a72048r-cvs_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a72048r-cvs_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "1.1.4",          "vulnera...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a72072r_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a72072r_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerabl...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a80316s_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a80316s_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerabl...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a80624s_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a80624s_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerabl...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a81016s_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a81016s_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerabl...

Source: nvd

Type: Configuration

Vendor: *

Product: ds-a82024d_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:hikvision:ds-a82024d_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.3.8-6",          "vulnerabl...

Source: nvd

End of list