7.5

CVE-2023-28809

Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HikvisionDs-k1t320efwx Firmware Version-
   HikvisionDs-k1t320efwx Version-
HikvisionDs-k1t320efx Firmware Version-
   HikvisionDs-k1t320efx Version-
HikvisionDs-k1t320ewx Firmware Version-
   HikvisionDs-k1t320ewx Version-
HikvisionDs-k1t320ex Firmware Version-
   HikvisionDs-k1t320ex Version-
HikvisionDs-k1t320mfwx Firmware Version-
   HikvisionDs-k1t320mfwx Version-
HikvisionDs-k1t320mfx Firmware Version-
   HikvisionDs-k1t320mfx Version-
HikvisionDs-k1t320mwx Firmware Version-
   HikvisionDs-k1t320mwx Version-
HikvisionDs-k1t320mx Firmware Version-
   HikvisionDs-k1t320mx Version-
HikvisionDs-k1t341am Firmware Version-
   HikvisionDs-k1t341am Version-
HikvisionDs-k1t341amf Firmware Version-
   HikvisionDs-k1t341amf Version-
HikvisionDs-k1t341cm Firmware Version-
   HikvisionDs-k1t341cm Version-
HikvisionDs-k1t343ewx Firmware Version-
   HikvisionDs-k1t343ewx Version-
HikvisionDs-k1t343ex Firmware Version-
   HikvisionDs-k1t343ex Version-
HikvisionDs-k1t343mwx Firmware Version-
   HikvisionDs-k1t343mwx Version-
HikvisionDs-k1t343mx Firmware Version-
   HikvisionDs-k1t343mx Version-
HikvisionDs-k1t671 Firmware Version-
   HikvisionDs-k1t671 Version-
HikvisionDs-k1t671m Firmware Version-
   HikvisionDs-k1t671m Version-
HikvisionDs-k1t671mf Firmware Version-
   HikvisionDs-k1t671mf Version-
HikvisionDs-k1t671t Firmware Version-
   HikvisionDs-k1t671t Version-
HikvisionDs-k1t671tm Firmware Version-
   HikvisionDs-k1t671tm Version-
HikvisionDs-k1t671tmf Firmware Version-
   HikvisionDs-k1t671tmf Version-
HikvisionDs-k1t671tmfw Firmware Version-
   HikvisionDs-k1t671tmfw Version-
HikvisionDs-k1t671tmw Firmware Version-
   HikvisionDs-k1t671tmw Version-
HikvisionDs-k1t804af Firmware Version-
   HikvisionDs-k1t804af Version-
HikvisionDs-k1t804amf Firmware Version-
   HikvisionDs-k1t804amf Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.336
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
hsrc@hikvision.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.