CVE-2024-47485: Critical severity Hikvision Hikcentral Master vulnerability
Published Oct 18, 2024
·Updated
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
Affected Software
1 affected component
Hikvision Hikcentral Master>=2.0.0<2.3.0
Event History
Oct 18, 2024
CVE Published
via MITRE·08:29 AM
Data Sourced
via MITRE·08:29 AM
Description
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47485?
CVE-2024-47485 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-47485?
To fix CVE-2024-47485, it is recommended to update HikCentral Master Lite to a version later than 2.3.0.
3
What systems are affected by CVE-2024-47485?
CVE-2024-47485 affects HikCentral Master Lite software versions between 2.0.0 and 2.3.0.
4
What type of attack does CVE-2024-47485 enable?
CVE-2024-47485 enables CSV injection attacks which can execute commands through manipulated CSV files.
5
Is there a specific version of HikCentral Master Lite to avoid for CVE-2024-47485?
Yes, HikCentral Master Lite versions 2.0.0 to 2.3.0 should be avoided to protect against CVE-2024-47485.