6.1
CVSSv3

CVE-2022-28172

Published: 27/06/2022 Updated: 23/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hikvision ds-a71024_firmware

hikvision ds-a71048_firmware

hikvision ds-a71072r_firmware

hikvision ds-a80624s_firmware

hikvision ds-a81016s_firmware

hikvision ds-a72024_firmware

hikvision ds-a72072r_firmware

hikvision ds-a80316s_firmware

hikvision ds-a82024d_firmware

hikvision ds-a71048r-cvs_firmware

hikvision ds-a72048r-cvs_firmware