CVE-2017-7921 is a critical improper authentication vulnerability (CWE-287) affecting numerous Hikvision DS-2CD, DS-2DF, and DS-2CD63xx series IP cameras and DVRs, allowing for privilege escalation and access to sensitive information. Rated with a CVSS v3.0 score of 10.0 (CRITICAL), this vulnerability can be exploited remotely with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, and has a very high EPSS score, indicating a high probability of exploitation. Public exploit code, including Metasploit modules for unauthenticated password changes and information disclosure, is readily available, contributing to its active hotlist status and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:hikvision:ds-2cd2032-i_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:hikvision:ds-2cd2112-i_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:hikvision:ds-2cd2132-i_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:hikvision:ds-2cd2212-i5_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:hikvision:ds-2cd2232-i5_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.