cve/2024/CVE-2024-29949.md

32 lines
2.1 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2024-29949](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29949)
![](https://img.shields.io/static/v1?label=Product&message=DS-7604NI-K1%20%2F%204P(B)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-7604NI-M1%2F4P&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-76xxNI-Mx&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-76xxNXI-Ix&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-77xxNI-Mx&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-77xxNXI-Ix&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-86xxNXI-Ix&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-96xxNXI-Ix&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=DS-96xxxNI-Mxx&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=iDS-76xxNXI-Mx&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=iDS-77xxNXI-Mx&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=iDS-96xxxMXI-Mxx&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20V4.30.096build221220%20and%20the%20versions%20prior%20to%20it%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Versions%20after%20V5.00.000%20(including%20V5.00.000)%20and%20before%20V5.01.070%EF%BC%88not%20including%20V5.01.070%EF%BC%89%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Versions%20after%20V5.00.000%20(including%20V5.00.000)%20and%20before%20V5.02.006%EF%BC%88not%20including%20V5.02.006%EF%BC%89%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/LOURC0D3/ENVY-gitbook
- https://github.com/LOURC0D3/LOURC0D3