CVE Vulnerabilities

CVE-2022-28173

Published: Dec 19, 2022 | Modified: Dec 29, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

Affected Software

Name Vendor Start Version End Version
Ds-3wf0ac-2nt_firmware Hikvision * 1.1.0 (excluding)

References