{"cve":"CVE-2024-58274","enrichment":{"created":"2025-10-23T13:11:57.185441+00:00","updated":"2025-10-23T13:11:57.185467+00:00","vendors":["hikvision","hikvision$PRODUCT$isecure_center"]},"epss":{"score":0.19085},"mitre":{"cpes":[],"created":"2025-10-22T00:00:00+00:00","description":"Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"},"cvssV4_0":{}},"mitre_repo_path":"cves/2024/58xxx/CVE-2024-58274.json","references":["https://forum.butian.net/article/498","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/hikvision/hikvision-csmp-installation-rce.yaml","https://xz.aliyun.com/news/14639"],"title":null,"updated":"2025-10-22T13:55:16.083000+00:00","vendors":[],"weaknesses":["CWE-78"]},"nvd":{"cpes":[],"created":"2025-10-22T04:15:55.680000+00:00","description":"Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"},"cvssV4_0":{}},"nvd_repo_path":"2024/CVE-2024-58274.json","references":["https://forum.butian.net/article/498","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/hikvision/hikvision-csmp-installation-rce.yaml","https://xz.aliyun.com/news/14639"],"title":null,"updated":"2026-06-17T08:14:45.083000+00:00","vendors":[],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-10-22T04:00:00+00:00","data":[{"details":{"new":"Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.","old":null},"type":"description"},{"details":{"added":["CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://forum.butian.net/article/498","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/hikvision/hikvision-csmp-installation-rce.yaml","https://xz.aliyun.com/news/14639"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":8.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"b23e8fab-2424-48c9-844a-3df378ac57a4"},{"created":"2025-10-22T14:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"a84911af-f251-49ef-b503-78f361aee35e"},{"created":"2025-10-23T13:15:00+00:00","data":[{"details":["hikvision","hikvision$PRODUCT$isecure_center"],"type":"first_time"},{"details":{"added":["hikvision","hikvision$PRODUCT$isecure_center"],"removed":[]},"type":"vendors"}],"id":"2930eb9f-a106-4651-9052-5d262b6c98b1"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2025-10-22T00:00:00+00:00","provider":"mitre"},"description":{"data":"Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.19085},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://forum.butian.net/article/498","https://github.com/ahisec/nuclei-tps/blob/main/http/vulnerabilities/hikvision/hikvision-csmp-installation-rce.yaml","https://xz.aliyun.com/news/14639"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":null,"provider":null},"updated":{"data":"2026-04-15T00:35:42.020000+00:00","provider":"nvd"},"vendors":{"data":["hikvision","hikvision$PRODUCT$isecure_center"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-10-22T00:00:00+00:00","description":"Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":["https://xz.aliyun.com/news/14639"],"title":null,"updated":"2025-10-22T13:55:06.602000+00:00","vendors":[],"vulnrichment_repo_path":"2024/58xxx/CVE-2024-58274.json","weaknesses":[]}}