RULE(RULE ID:338497)

Rule General Information
Release Date: 2024-10-29
Rule Name: HIKVISION iSecure Center download Interface Arbitrary File Reading Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The HIKVISION iSecure Center platform is an intelligent platform that centrally manages access video surveillance for unified deployment and scheduling. HIKVISION iSecure Center platform orgManage/v1/orgs/download interface has read arbitrary files loopholes, the attacker can construct malicious request, through holes to read arbitrary files on the server.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.