ID

VAR-202104-2036


TITLE

Any file reading vulnerability exists in the access network of Hangzhou Hikvision System Technology Co., Ltd. video encoding equipment

Trust: 0.6

sources: CNVD: CNVD-2021-16003

DESCRIPTION

Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions. The video encoding equipment access network of Hangzhou Hikvision System Technology Co., Ltd. has an arbitrary file reading vulnerability. Attackers can use this vulnerability to read all files to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2021-16003

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-16003

AFFECTED PRODUCTS

vendor:hikvision systemmodel:video coding equipment access gatewayscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-16003

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-16003
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-16003
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-16003

EXTERNAL IDS

db:CNVDid:CNVD-2021-16003

Trust: 0.6

sources: CNVD: CNVD-2021-16003

SOURCES

db:CNVDid:CNVD-2021-16003

LAST UPDATE DATE

2022-05-04T09:08:35.150000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-16003date:2021-03-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-16003date:2021-04-09T00:00:00