Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson
Vulnerability Description
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger Fastjson's auto-type feature to load arbitrary Java classes. By referencing a malicious class via an LDAP URL, an attacker can achieve remote code execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Hikvision HikCentral 安全漏洞
Vulnerability Description
Hikvision HikCentral是中国海康威视(Hikvision)公司的一款安全管理软件。 Hikvision HikCentral存在安全漏洞,该漏洞源于反序列化问题,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A