6.5

CVE-2022-28172

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HikvisionDs-a71024 Firmware Version <= 2.3.8-6
   HikvisionDs-a71024 Version-
HikvisionDs-a71048 Firmware Version <= 2.3.8-6
   HikvisionDs-a71048 Version-
HikvisionDs-a71072r Firmware Version <= 2.3.8-6
   HikvisionDs-a71072r Version-
HikvisionDs-a80624s Firmware Version <= 2.3.8-6
   HikvisionDs-a80624s Version-
HikvisionDs-a81016s Firmware Version <= 2.3.8-6
   HikvisionDs-a81016s Version-
HikvisionDs-a72024 Firmware Version <= 2.3.8-6
   HikvisionDs-a72024 Version-
HikvisionDs-a72072r Firmware Version <= 2.3.8-6
   HikvisionDs-a72072r Version-
HikvisionDs-a80316s Firmware Version <= 2.3.8-6
   HikvisionDs-a80316s Version-
HikvisionDs-a82024d Firmware Version <= 2.3.8-6
   HikvisionDs-a82024d Version-
HikvisionDs-a71024 Firmware Version <= 1.1.4
   HikvisionDs-a71024 Version-
HikvisionDs-a71048r-cvs Firmware Version <= 1.1.4
   HikvisionDs-a71048r-cvs Version-
HikvisionDs-a72024 Firmware Version <= 1.1.4
   HikvisionDs-a72024 Version-
HikvisionDs-a72048r-cvs Firmware Version <= 1.1.4
   HikvisionDs-a72048r-cvs Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.688
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
hsrc@hikvision.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.