Hikvision security notification-CVE-2021-36260
NAME
Hikvision – Multiple
- Platforms Affected:
Multiple - Risk Level:
high - CVE Type:
Command Injection
DESCRIPTION
CVE-2021-36260 is a command injection vulnerability impacting multiple Hikvision products. A Metasploit module was observed in open source and a link to an exploit was shared in the underground.
CVSS Information:
- CVSS 2.0 SCORE: 9.3
- CVSS 3.0 SCORE: 9.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://packetstormsecurity[.]com/files/164603/Hikvision-Web-Server-Build-210702-Command-Injection[.]html
MITIGATION
Hikvision addressed the vulnerability in security notification with updated versions.
- Reference Link:
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/security-notification-command-injection-vulnerability-in-some-hikvision-products/ - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.