ID

VAR-201706-1109


TITLE

Hikvision Vehicle Remote Monitoring System CUInfoHandle.php File CUID Parameter SQL Injection Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-05895

DESCRIPTION

Hikvision vehicle remote monitoring system is a set of vehicle video network monitoring platform software. Hikvision vehicle remote monitoring system CUInfoHandle.php file parameter CUID has SQL injection vulnerability. Allows attackers to exploit vulnerabilities to obtain database sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2017-05895

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-05895

AFFECTED PRODUCTS

vendor:hikvision digitalmodel:vehicle remote monitoring systemscope:eqversion:v2.3

Trust: 0.6

sources: CNVD: CNVD-2017-05895

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-05895
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-05895
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-05895

EXTERNAL IDS

db:CNVDid:CNVD-2017-05895

Trust: 0.6

sources: CNVD: CNVD-2017-05895

SOURCES

db:CNVDid:CNVD-2017-05895

LAST UPDATE DATE

2022-05-04T10:12:08.581000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-05895date:2017-06-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-05895date:2017-06-14T00:00:00