Back to overview

CVE-2023-28815

CRITICAL
9.8
CVSS 3.1
Description
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the system.iSecure Center is software released for China's domestic market only, with no overseas release.

Metadata

CVE ID
CVE-2023-28815
State
PUBLISHED
Assigner
hikvision
Reserved
2023-03-23 19:49 UTC
Published
2025-10-17 11:07 UTC
Last updated
2025-10-17 12:10 UTC
Primary CWE
CWE-141
CWE-141 Improper Neutralization of Parameter/Argument Delimi…
Vendor / Product
Hikvision / iSecure Center
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Hikvision iSecure Center V1.0.0 - V1.7.0
Weakness (CWE)
CWESourceDescription
CWE-141 adp CWE-141 Improper Neutralization of Parameter/Argument Delimiters
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview