CVE-2024-29949

EUVD-2024-26923
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
hikvisionds-7604ni-k1\/4p\(b\)
𝑥
≤ V4.30.096build221220
ADP
hikvisionds-76xxni-mx
V5.00.000 ≤
𝑥
< V5.02.006
ADP
hikvisionds-77xxni-mx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionds-96xxxni-mxx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionds-76xxnxi-lx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionds-77xxnxi-lx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionds-86xxnxi-lx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionds-96xxnxi-lx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionids-76xxnxi-mx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionids-77xxnxi-mx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionids-96xxxmxi-mxx
5.00.000 ≤
𝑥
< 5.02.006
ADP
hikvisionds-7604ni-m1\/4p
5.00.000 ≤
𝑥
< 5.01.070
ADP