漏洞信息
# N/A
## 漏洞概述
Hikvision多个系列设备存在身份验证不当的漏洞,这可能导致恶意用户提升权限并访问敏感信息。
## 影响版本
- DS-2CD2xx2F-I Series: V5.2.0 build 140721至V5.4.0 build 160530
- DS-2CD2xx0F-I Series: V5.2.0 build 140721至V5.4.0 Build 160401
- DS-2CD2xx2FWD Series: V5.3.1 build 150410至V5.4.4 Build 161125
- DS-2CD4x2xFWD Series: V5.2.0 build 140721至V5.4.0 Build 160414
- DS-2CD4xx5 Series: V5.2.0 build 140721至V5.4.0 Build 160421
- DS-2DFx Series: V5.2.0 build 140805至V5.4.5 Build 160928
- DS-2CD63xx Series: V5.0.9 build 140305至V5.3.5 Build 160106
## 漏洞细节
该漏洞存在于应用未能充分或正确验证用户身份的情况下,导致身份验证不当。
## 影响
恶意用户可以利用该漏洞提升自身在系统中的权限,并访问敏感信息。
备注
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
N/A
漏洞描述信息
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
CVSS信息
N/A
漏洞类别
认证机制不恰当
漏洞标题
多款Hikvision产品安全漏洞
漏洞描述信息
Hikvision DS-2CD2xx2F-I Series等都是中国海康威视(Hikvision)公司的网络摄像头产品。 多款Hikvision产品中存在身份验证漏洞。攻击者可利用该漏洞提升权限,获取敏感信息的访问权限。以下产品和版本受到影响:Hikvision DS-2CD2xx2F-I Series 5.2.0 build 140721版本至5.4.0 build 160530版本;DS-2CD2xx0F-I Series 5.2.0 build 140721版本至5.4.0 Build 16040
CVSS信息
N/A
漏洞类别
授权问题