4.3

CVE-2023-28810

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HikvisionDs-k1t804af Firmware Version <= 1.4.0_build221212
   HikvisionDs-k1t804af Version-
HikvisionDs-k1t804amf Firmware Version <= 1.4.0_build221212
   HikvisionDs-k1t804amf Version-
HikvisionDs-k1t341am Firmware Version <= 3.2.30_build221223
   HikvisionDs-k1t341am Version-
HikvisionDs-k1t341amf Firmware Version <= 3.2.30_build221223
   HikvisionDs-k1t341amf Version-
HikvisionDs-k1t671m Firmware Version <= 3.2.30_build221223
   HikvisionDs-k1t671m Version-
HikvisionDs-k1t671mf Firmware Version <= 3.2.30_build221223
   HikvisionDs-k1t671mf Version-
HikvisionDs-k1t671 Firmware Version <= 3.2.30_build221223
   HikvisionDs-k1t671 Version-
HikvisionDs-k1t343efwx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343efwx Version-
HikvisionDs-k1t343efx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343efx Version-
HikvisionDs-k1t343ewx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343ewx Version-
HikvisionDs-k1t343ex Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343ex Version-
HikvisionDs-k1t343mfwx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343mfwx Version-
HikvisionDs-k1t343mfx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343mfx Version-
HikvisionDs-k1t343mwx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343mwx Version-
HikvisionDs-k1t343mx Firmware Version <= 3.14.0_build230117
   HikvisionDs-k1t343mx Version-
HikvisionDs-k1t341c Firmware Version <= 3.3.8_build230112
   HikvisionDs-k1t341c Version-
HikvisionDs-k1t320efwx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320efwx Version-
HikvisionDs-k1t320efx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320efx Version-
HikvisionDs-k1t320ewx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320ewx Version-
HikvisionDs-k1t320ex Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320ex Version-
HikvisionDs-k1t320mfwx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320mfwx Version-
HikvisionDs-k1t320mfx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320mfx Version-
HikvisionDs-k1t320mwx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320mwx Version-
HikvisionDs-k1t320mx Firmware Version <= 3.5.0_build220706
   HikvisionDs-k1t320mx Version-
HikvisionDs-kh6320-wte1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6320-wte1 Version-
HikvisionDs-kh6350-wte1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6350-wte1 Version-
HikvisionDs-kh6351-te1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6351-te1 Version-
HikvisionDs-kh6351-wte1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6351-wte1 Version-
HikvisionDs-kh6320-le1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6320-le1 Version-
HikvisionDs-kh63le1(b) Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh63le1(b) Version-
HikvisionDs-kh6320-tde1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6320-tde1 Version-
HikvisionDs-kh6320-te1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6320-te1 Version-
HikvisionDs-kh6320-wtde1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh6320-wtde1 Version-
HikvisionDs-kh8520-wte1 Firmware Version <= 2.2.8_build230219
   HikvisionDs-kh8520-wte1 Version-
HikvisionDs-kh6220-le1 Firmware Version <= 1.4.62_build220414
   HikvisionDs-kh6220-le1 Version-
HikvisionDs-kh9310-wte1(b) Firmware Version <= 2.1.76_build230204
   HikvisionDs-kh9310-wte1(b) Version-
HikvisionDs-kh9510-wte1(b) Firmware Version <= 2.1.76_build230204
   HikvisionDs-kh9510-wte1(b) Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.603
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
hsrc@hikvision.com 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.