RULE(RULE ID:338615)

Rule General Information
Release Date: 2024-12-24
Rule Name: Hikvision iSecure Center applyST Remote Code Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Hikvision iSecure Center is a centralized control platform developed by Hikvision for enterprise-level security management. It integrates functions such as resource monitoring, configuration management, and alarm handling to improve O-M efficiency and system stability. The system uses a low version of fastjson, the attacker can obtain the server permission without authentication, and because of the dependency, even if the server is not out of the network can not remotely load the malicious class can also be executed through the local chain direct command, so as to obtain the server permission.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.