Command Injection Vulnerability in Hikvision's iSecure Center Software
CVE-2023-28815
9.8CRITICAL
What is CVE-2023-28815?
A command injection vulnerability exists in Hikvision's iSecure Center software due to insufficient parameter validation. This flaw allows attackers to exploit the system, potentially gaining unauthorized platform privileges and executing arbitrary commands. It is important to note that this product is specifically designed for the domestic market in China, with no international release. Vigilance is required to prevent unauthorized access and ensure system integrity.
Affected Version(s)
iSecure Center V1.0.0 - V1.7.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
hsrc
