9.8
CVSSv3

CVE-2022-28171

Published: 27/06/2022 Updated: 02/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hikvision ds-a71024_firmware

hikvision ds-a71048_firmware

hikvision ds-a71072r_firmware

hikvision ds-a80624s_firmware

hikvision ds-a81016s_firmware

hikvision ds-a72024_firmware

hikvision ds-a72072r_firmware

hikvision ds-a80316s_firmware

hikvision ds-a82024d_firmware

hikvision ds-a71048r-cvs_firmware

hikvision ds-a72048r-cvs_firmware

Exploits

Hikvision Hybrid SAN Ds-a71024 firmware suffers from a remote blind SQL injection vulnerability ...

Github Repositories

CVE-2022-28171-POC I originally published this on ExploitDB, which you can find at wwwexploit-dbcom/exploits/51607 Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution # Date: 16 July 2023 # Exploit Author: Thurein Soe # CVE : CVE-2022-28171 # Reference Link: cvereport/CVE-2022-28171 # Vulnerable Versions: Ds-a71024 Firmware Ds-a71024 Fir