peter bassill · operator
$ cve CVE-2022-28171 JSON

CVE-2022-28171 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 51.6% (pctl 99)

Patch early

A public exploit exists.

Description

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS51.64% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2022-06-27
Last modified2026-06-17

Affected (22)

VendorProduct
hikvisionds-a71024
hikvisionds-a71024 firmware
hikvisionds-a71048
hikvisionds-a71048 firmware
hikvisionds-a71048r-cvs
hikvisionds-a71048r-cvs firmware
hikvisionds-a71072r
hikvisionds-a71072r firmware
hikvisionds-a72024
hikvisionds-a72024 firmware
hikvisionds-a72048r-cvs
hikvisionds-a72048r-cvs firmware
hikvisionds-a72072r
hikvisionds-a72072r firmware
hikvisionds-a80316s
hikvisionds-a80316s firmware
hikvisionds-a80624s
hikvisionds-a80624s firmware
hikvisionds-a81016s
hikvisionds-a81016s firmware
hikvisionds-a82024d
hikvisionds-a82024d firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD