ID

VAR-201610-0731


TITLE

Hikvision Elisa Live IP camera has an XXE external entity injection vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-09329

DESCRIPTION

Hangzhou Hikvision Digital Technology Co., Ltd. ElisaLiveIPcamera is a network camera. Hikvision ElisaLiveIPcamera has an XXE external entity injection vulnerability. An attacker can exploit the vulnerability to obtain arbitrary files on the website, and severely obtain server control rights.

Trust: 0.6

sources: CNVD: CNVD-2016-09329

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-09329

AFFECTED PRODUCTS

vendor:hikvision digitalmodel:elisa live ip camerascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-09329

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-09329
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-09329
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-09329

PATCH

title:Hikvision remote system has a patch for XXE external entity injection vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/82488

Trust: 0.6

sources: CNVD: CNVD-2016-09329

EXTERNAL IDS

db:CNVDid:CNVD-2016-09329

Trust: 0.6

sources: CNVD: CNVD-2016-09329

REFERENCES

url:https://medium.com/@iraklis/an

Trust: 0.6

sources: CNVD: CNVD-2016-09329

SOURCES

db:CNVDid:CNVD-2016-09329

LAST UPDATE DATE

2022-05-04T09:34:28.894000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-09329date:2016-10-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-09329date:2016-10-18T00:00:00