VYPR

NVRs

by Hikvision

CVEs (3)

  • CVE-2024-29949HigApr 2, 2024
    risk 0.47cvss 7.2epss 0.01

    There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.

  • CVE-2024-29948LowApr 2, 2024
    risk 0.25cvss 3.8epss 0.00

    There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.

  • CVE-2024-29947LowApr 2, 2024
    risk 0.18cvss 2.7epss 0.00

    There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality.