CVE-2017-14953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
01/12/2017
Last modified:
20/04/2025

Description

HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication. NOTE: Vendor states that this is not a vulnerability, but more an increase to the attack surface of the product

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hikvision:ds-2cd2432f-iw_firmware:*:*:*:*:*:*:*:* 5.4.5 (excluding)
cpe:2.3:h:hikvision:ds-2cd2432f-iw:-:*:*:*:*:*:*:*