'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2023-6895:Hikvision Intercom Broadcasting System ping.php Command Injection Vulnerability
Severity:critical
CVE ID:CVE-2023-6895
| Descripiton:
|
Hikvision Intercom Broadcasting System is an intercom broadcasting system developed by Hikvision Corporation in China. Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) There is an operating system command injection vulnerability in the version, which is caused by the parameter 'json data [ip]' in the file/php/ping. php, which can lead to the injection of operating system commands.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.