Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wcj-3gqq-r8fv

Опубликовано: 22 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

EPSS

Процентиль: 97%
0.17885
Средний

8.3 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.3
nvd
11 месяцев назад

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

CVSS3: 8.3
fstec
около 2 лет назад

Уязвимость интегрированной платформы управления безопасностью Hikvision CSMP iSecure Center, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 97%
0.17885
Средний

8.3 High

CVSS3

Дефекты

CWE-78