CVE-2023-28808

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hikvision:ds-a71024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71024:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hikvision:ds-a71048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71048:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hikvision:ds-a71072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71072r:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hikvision:ds-a80624s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a80624s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hikvision:ds-a81016s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a81016s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hikvision:ds-a72024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a72024:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hikvision:ds-a72072r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a72072r:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hikvision:ds-a80316s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a80316s:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hikvision:ds-a82024d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a82024d:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hikvision:ds-a71024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71024:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hikvision:ds-a71048r-cvs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71048r-cvs:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hikvision:ds-a72072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a72072r:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.1
References () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-cluster-stor/ - Vendor Advisory () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-cluster-stor/ - Vendor Advisory

Information

Published : 2023-04-11 21:15

Updated : 2024-11-21 07:56


NVD link : CVE-2023-28808

Mitre link : CVE-2023-28808

CVE.ORG link : CVE-2023-28808


JSON object : View

Products Affected

hikvision

  • ds-a71024
  • ds-a71024_firmware
  • ds-a80624s_firmware
  • ds-a81016s_firmware
  • ds-a71048_firmware
  • ds-a82024d
  • ds-a80316s
  • ds-a71048r-cvs_firmware
  • ds-a80624s
  • ds-a72024_firmware
  • ds-a71072r_firmware
  • ds-a71048
  • ds-a72024
  • ds-a71072r
  • ds-a82024d_firmware
  • ds-a80316s_firmware
  • ds-a71048r-cvs
  • ds-a72072r
  • ds-a81016s
  • ds-a72072r_firmware
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo