CVE-2023-28809

S

ome access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320efwx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320efwx:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320efx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320efx:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320ewx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320ewx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320ex_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320ex:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320mfwx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320mfwx:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320mfx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320mfx:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320mwx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320mwx:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t320mx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t320mx:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t341am_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t341am:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t341amf_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t341amf:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t341cm_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t341cm:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t343ewx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t343ewx:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t343ex_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t343ex:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t343mwx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t343mwx:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t343mx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t343mx:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671m:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671mf_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671mf:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671t_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671t:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671tm_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671tm:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671tm-3xf_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671tm-3xf:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671tmf_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671tmf:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671tmfw_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671tmfw:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t671tmw_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t671tmw:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t804af_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t804af:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:hikvision:ds-k1t804amf_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-k1t804amf:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:56

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/174506/Hikvision-Access-Control-Session-Hijacking.html - () http://packetstormsecurity.com/files/174506/Hikvision-Access-Control-Session-Hijacking.html -
References () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-access-control-intercom/ - Vendor Advisory () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-access-control-intercom/ - Vendor Advisory