Security Notice - Statement on Insecure Cookie Handling Vulnerability in hik-connect.com

Security Notice - Statement on Insecure Cookie Handling Vulnerability in hik-connect.com

SN No: HSRC-201804-09

Edit: Hikvision Security Response Center (HSRC)

Initial Release Date: 2018-04-24

On April 23, 2018, HSRC (Hikvision Security Response Center) received the report of "Insecure Cookie Handling" vulnerability in "hik-connect.com" from Vangelis Stykas and George Lavdanis.

HSRC has immediately checked all cloud service platforms, confirming that only "hik-connect.com" was affected. All repairs have been completed by 2 p.m. on April 24.HSRC is not aware of any public or malicious use launch to attack through the vulnerability described in this advisory.

This vulnerability was reported to HSRC by Vangelis Stykas & George Lavdanis. HSRC would like to thank Vangelis Stykas & George Lavdanis for working with us and coordinating vulnerability disclosure to protect our customers.

Contact Us

For security problems about Hikvision products and solutions, please contact Hikvision Security Response Center at hsrc@hikvision.com.  

이 웹사이트는 웹사이트가 정상적으로 작동 할 수 있도록 필요한 쿠키를 사용합니다. 당사 웹사이트에서 최상의 경험을 제공하기 위해 추가 쿠키를 사용하고자 합니다. 더 많은 정보를 위해 쿠키 정책을 확인하세요.

문의하기