GobyVuls/Hikvision_iSecure_Center_springboot_Information_disclosure_vulnerability.md

1.4 KiB

Hikvision iSecure Center springboot Information disclosure vulnerability

Vulnerability Hikvision iSecure Center springboot Information disclosure vulnerability
Chinese name 海康综合安防管理平台系统 springboot 信息泄露漏洞
CVSS core 7.5
FOFA Query (click to view the results directly) title="综合安防管理平台" && body="nginxService/v1/download/InstallRootCert.exe"
Number of assets affected 3095
Description Hikvision iSecure Center is an integrated management platform, which can centrally manage the access video monitoring points to achieve unified deployment, configuration, management and scheduling. the framework it uses has a spring boot information disclosure vulnerability. An attacker can access the exposed route to obtain information such as environment variables, intranet addresses, and user names in the configuration.
Impact Hikvision iSecure Center is a spring boot information disclosure vulnerability. An attacker can access and download the heapdump heap to obtain sensitive information such as the intranet account password.