ID

VAR-201710-1440


TITLE

Hikvision has design logic loopholes

Trust: 0.6

sources: CNVD: CNVD-2017-25034

DESCRIPTION

Hikvision DS-2CD2710F-I and DS-5C-I Series are webcam products developed by China Hikvision. Hikvision has loopholes in design logic, and failed to correctly verify the wrong parameters when receiving and processing standard parameters. An attacker could use the vulnerability to cause the device to restart.

Trust: 0.6

sources: CNVD: CNVD-2017-25034

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-25034

AFFECTED PRODUCTS

vendor:hikvision digitalmodel:ds-2cd2710f-1 buildscope:eqversion:v5.3.0150513

Trust: 0.6

vendor:hikvision digitalmodel:ds-5c-i buildscope:eqversion:v5.3.0150513

Trust: 0.6

sources: CNVD: CNVD-2017-25034

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-25034
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2017-25034
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-25034

EXTERNAL IDS

db:CNVDid:CNVD-2017-25034

Trust: 0.6

sources: CNVD: CNVD-2017-25034

SOURCES

db:CNVDid:CNVD-2017-25034

LAST UPDATE DATE

2022-05-04T09:56:43.886000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-25034date:2017-10-03T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-25034date:2017-10-02T00:00:00