target entity

Hikvision

2 source-linked records in the current knowledge graph.

high

CVE-2017-7921: Hikvision Multiple Products Improper Authentication Vulnerability

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2017-7921EPSS 100.0%HikvisionMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-36260: Hikvision Improper Input Validation

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. Required action: Apply updates per vendor instructions.

CVE-2021-36260EPSS 99.9%HikvisionSecurity cameras web server
CISA KEV ↗ · unattributed attribution