CVE-2022-28171: Command Injection
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device.
Credit
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-28171?
CVE-2022-28171 is a security vulnerability present in some Hikvision Hybrid SAN/Cluster Storage products that allows attackers to execute restricted commands.
Which Hikvision products are affected by CVE-2022-28171?
Hikvision Ds-a71024, Hikvision Ds-a71048, Hikvision Ds-a71072r, Hikvision Ds-a80624s, Hikvision Ds-a81016s, Hikvision Ds-a72024, Hikvision Ds-a72072r, Hikvision Ds-a80316s, and Hikvision Ds-a82024d are affected by CVE-2022-28171.
What is the severity of CVE-2022-28171?
CVE-2022-28171 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2022-28171?
Attackers can exploit CVE-2022-28171 by sending messages with malicious commands to the affected device, taking advantage of insufficient input validation.
Are there any known references for CVE-2022-28171?
Yes, you can find references for CVE-2022-28171 at the following links: [Exploit-DB](https://www.exploit-db.com/exploits/51607), [Packet Storm Security](http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.html), [Packet Storm Security](http://packetstormsecurity.com/files/173653/Hikvision-Hybrid-SAN-Ds-a71024-SQL-Injection.html)