9.8

CVE-2023-28808

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HikvisionDs-a71024 Firmware Version <= 2.3.8-8
   HikvisionDs-a71024 Version-
HikvisionDs-a71048 Firmware Version <= 2.3.8-8
   HikvisionDs-a71048 Version-
HikvisionDs-a71072r Firmware Version <= 2.3.8-8
   HikvisionDs-a71072r Version-
HikvisionDs-a80624s Firmware Version <= 2.3.8-8
   HikvisionDs-a80624s Version-
HikvisionDs-a81016s Firmware Version <= 2.3.8-8
   HikvisionDs-a81016s Version-
HikvisionDs-a72024 Firmware Version <= 2.3.8-8
   HikvisionDs-a72024 Version-
HikvisionDs-a72072r Firmware Version-
   HikvisionDs-a72072r Version-
HikvisionDs-a80316s Firmware Version <= 2.3.8-8
   HikvisionDs-a80316s Version-
HikvisionDs-a82024d Firmware Version <= 2.3.8-8
   HikvisionDs-a82024d Version-
HikvisionDs-a71024 Firmware Version <= 1.1.4
   HikvisionDs-a71024 Version-
HikvisionDs-a71048r-cvs Firmware Version <= 1.1.4
   HikvisionDs-a71048r-cvs Version-
HikvisionDs-a72072r Firmware Version <= 2.3.8-8
   HikvisionDs-a72072r Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.695
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
hsrc@hikvision.com 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.