CVE Database
/

CVE-2023-28809

Back to search

CVE-2023-28809

Published: Jun 15, 2023

Modified: Dec 18, 2024

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.

VendorProductVersions

hikvision

DS-K1T804AXX

affected
V1.4.0_build221212 - < V1.4.0_build221212

hikvision

DS-K1T341AXX

affected
V3.2.30_build221223 - < V3.2.30_build221223

hikvision

DS-K1T671XXX

affected
V3.2.30_build221223 - < V3.2.30_build221223

hikvision

DS-K1T343XXX

affected
V3.14.0_build230117 - < V3.14.0_build230117

hikvision

DS-K1T341C

affected
V3.3.8_build230112 - < V3.3.8_build230112

hikvision

DS-K1T320XXX

affected
V3.5.0_build220706 - < V3.5.0_build220706

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now