9.8

CVE-2021-36260

Warnung
Exploit
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HikvisionDs-2cd2426g2-i Firmware Version-
   HikvisionDs-2cd2426g2-i Version-
HikvisionDs-2cd2446g2-i Firmware Version-
   HikvisionDs-2cd2446g2-i Version-
HikvisionDs-2cd2121g1 Firmware Version-
   HikvisionDs-2cd2121g1 Version-
HikvisionPtz-n2204i-de3 Firmware Version-
   HikvisionPtz-n2204i-de3 Version-
HikvisionPtz-n2404i-de3 Firmware Version-
   HikvisionPtz-n2404i-de3 Version-
HikvisionPtz-n4215-de3 Firmware Version-
   HikvisionPtz-n4215-de3 Version-
HikvisionPtz-n4215i-de Firmware Version-
   HikvisionPtz-n4215i-de Version-
HikvisionPtz-n4225i-de Firmware Version-
   HikvisionPtz-n4225i-de Version-
HikvisionPtz-n5225i-a Firmware Version-
   HikvisionPtz-n5225i-a Version-
HikvisionDs-2td4136t-9 Firmware Version-
   HikvisionDs-2td4136t-9 Version-
HikvisionDs-2td4166t-9 Firmware Version-
   HikvisionDs-2td4166t-9 Version-
HikvisionDs-7604ni-k1 Firmware Version-
   HikvisionDs-7604ni-k1 Version-
HikvisionDs-7608ni-k1 Firmware Version-
   HikvisionDs-7608ni-k1 Version-
HikvisionDs-7616ni-k1 Firmware Version >= 4.30.210 <= 4.31.000
   HikvisionDs-7616ni-k1 Version-
HikvisionDs-7604ni-q1 Firmware Version >= 4.30.210 <= 4.31.000
   HikvisionDs-7604ni-q1 Version-
HikvisionDs-7608ni-q1 Firmware Version >= 4.30.210 <= 4.31.000
   HikvisionDs-7608ni-q1 Version-
HikvisionDs-7608ni-q2 Firmware Version >= 4.30.210 <= 4.31.000
   HikvisionDs-7608ni-q2 Version-
HikvisionDs-7616ni-q1 Firmware Version >= 4.30.210 <= 4.31.000
   HikvisionDs-7616ni-q1 Version-
HikvisionDs-7616ni-q2 Firmware Version >= 4.30.210 <= 4.31.000
   HikvisionDs-7616ni-q2 Version-
HikvisionDs-7104ni-q1 Firmware Version >= 4.30.300 <= 4.31.100
   HikvisionDs-7104ni-q1 Version-
HikvisionDs-7108ni-q1 Firmware Version >= 4.30.300 <= 4.31.100
   HikvisionDs-7108ni-q1 Version-

10.01.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Hikvision Improper Input Validation

Schwachstelle

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.44% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.