7.5
CVE-2023-28809
- EPSS 0.13%
- Veröffentlicht 15.06.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:56:03
- Quelle hsrc@hikvision.com
- CVE-Watchlists
- Unerledigt
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hikvision ≫ Ds-k1t320efwx Firmware Version-
Hikvision ≫ Ds-k1t320efx Firmware Version-
Hikvision ≫ Ds-k1t320ewx Firmware Version-
Hikvision ≫ Ds-k1t320ex Firmware Version-
Hikvision ≫ Ds-k1t320mfwx Firmware Version-
Hikvision ≫ Ds-k1t320mfx Firmware Version-
Hikvision ≫ Ds-k1t320mwx Firmware Version-
Hikvision ≫ Ds-k1t320mx Firmware Version-
Hikvision ≫ Ds-k1t341am Firmware Version-
Hikvision ≫ Ds-k1t341amf Firmware Version-
Hikvision ≫ Ds-k1t341cm Firmware Version-
Hikvision ≫ Ds-k1t343ewx Firmware Version-
Hikvision ≫ Ds-k1t343ex Firmware Version-
Hikvision ≫ Ds-k1t343mwx Firmware Version-
Hikvision ≫ Ds-k1t343mx Firmware Version-
Hikvision ≫ Ds-k1t671 Firmware Version-
Hikvision ≫ Ds-k1t671m Firmware Version-
Hikvision ≫ Ds-k1t671mf Firmware Version-
Hikvision ≫ Ds-k1t671t Firmware Version-
Hikvision ≫ Ds-k1t671tm Firmware Version-
Hikvision ≫ Ds-k1t671tm-3xf Firmware Version-
Hikvision ≫ Ds-k1t671tmf Firmware Version-
Hikvision ≫ Ds-k1t671tmfw Firmware Version-
Hikvision ≫ Ds-k1t671tmw Firmware Version-
Hikvision ≫ Ds-k1t804af Firmware Version-
Hikvision ≫ Ds-k1t804amf Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.336 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| hsrc@hikvision.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-384 Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.