CVE-2021-36260

CRITICAL(9.8)KEVWahrscheinlich ausgenutzt

Hikvision Improper Input Validation

Beschreibung

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

KEV-Informationen

Hersteller
Hikvision
Produkt
Security cameras web server
Hinzugefügt am
10. Januar 2022
Fälligkeitsdatum
24. Januar 2022
Erforderliche Maßnahme
Apply updates per vendor instructions.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
hikvisionds-2cd2026g2-iu\/sl firmware-
hikvisionds-2cd2046g2-iu\/sl firmware-
hikvisionds-2cd2066g2-i\(u\) firmware-
hikvisionds-2cd2066g2-iu\/sl firmware-
hikvisionds-2cd2086g2-i\(u\) firmware-
hikvisionds-2cd2086g2-iu\/sl firmware-
hikvisionds-2cd2166g2-i\(su\) firmware-
hikvisionds-2cd2186g2-i\(su\) firmware-
hikvisionds-2cd2186g2-isu firmware-
hikvisionds-2cd2326g2-isu\/sl firmware-
hikvisionds-2cd2346g2-isu\/sl firmware-
hikvisionds-2cd2366g2-i\(u\) firmware-
hikvisionds-2cd2366g2-isu\/sl firmware-
hikvisionds-2cd2386g2-i\(u\) firmware-
hikvisionds-2cd2386g2-isu\/sl firmware-
hikvisionds-2cd2426g2-i firmware-
hikvisionds-2cd2446g2-i firmware-
hikvisionds-2cd2526g2-i\(s\) firmware-
hikvisionds-2cd2526g2-is firmware-
hikvisionds-2cd2546g2-i\(s\) firmware-

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Referenzen

CVSS-Score

9.8
CRITICAL(9.8)

EPSS-Score

EPSS-Score99.87%
EPSS-Perzentil100.0%

Daten

Veröffentlicht22. September 2021
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.