CVE-2024-29949: Command Injection
Published Apr 2, 2024
·Updated
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.
Affected Software
1 affected component
Hikvision Hikvision Network Video Recorder (NVR)
Event History
Apr 2, 2024
CVE Published
via MITRE·11:07 AM
Data Sourced
via MITRE·11:07 AM
DescriptionSeverity
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29949?
CVE-2024-29949 has a high severity rating due to its potential to allow unauthorized command execution.
2
How do I fix CVE-2024-29949?
To mitigate CVE-2024-29949, apply the latest firmware updates provided by Hikvision for your NVR model.
3
Who is affected by CVE-2024-29949?
CVE-2024-29949 affects certain models of Hikvision Network Video Recorders that have administrative login access.
4
What happens if I don't address CVE-2024-29949?
Failure to address CVE-2024-29949 may lead to unauthorized control and manipulation of the video recording system.
5
Can CVE-2024-29949 be exploited remotely?
CVE-2024-29949 requires authentication, meaning only authenticated users can potentially exploit the command injection vulnerability.