CVE-2022-28172: XSS
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this security vulnerability?
The vulnerability ID for this security vulnerability is CVE-2022-28172.
What is the severity level of CVE-2022-28172?
The severity level of CVE-2022-28172 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2022-28172?
The affected software for CVE-2022-28172 includes some Hikvision Hybrid SAN/Cluster Storage products with specific firmware versions.
How can an attacker exploit CVE-2022-28172?
An attacker can exploit CVE-2022-28172 by sending messages with malicious commands to the affected device, leading to XSS attacks.
Are there any references for CVE-2022-28172?
Yes, there are references available for CVE-2022-28172. You can find them at the following links: [link1](http://packetstormsecurity.com/files/170818/Hikvision-Remote-Code-Execution-XSS-SQL-Injection.html) and [link2](https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/).