CVE-2023-28808

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hikvision:ds-a71024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71024:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hikvision:ds-a71048_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71048:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hikvision:ds-a71072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71072r:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hikvision:ds-a80624s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a80624s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hikvision:ds-a81016s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a81016s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hikvision:ds-a72024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a72024:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hikvision:ds-a72072r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a72072r:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hikvision:ds-a80316s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a80316s:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hikvision:ds-a82024d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a82024d:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hikvision:ds-a71024_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71024:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hikvision:ds-a71048r-cvs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a71048r-cvs:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hikvision:ds-a72072r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-a72072r:-:*:*:*:*:*:*:*

History

24 Apr 2023, 13:50

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 21:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-28808

Mitre link : CVE-2023-28808

CVE.ORG link : CVE-2023-28808


JSON object : View

Products Affected

hikvision

  • ds-a80316s_firmware
  • ds-a71024_firmware
  • ds-a72072r
  • ds-a71072r
  • ds-a71024
  • ds-a71048
  • ds-a80624s
  • ds-a72024
  • ds-a80316s
  • ds-a80624s_firmware
  • ds-a71048r-cvs
  • ds-a71048_firmware
  • ds-a82024d_firmware
  • ds-a71072r_firmware
  • ds-a81016s
  • ds-a81016s_firmware
  • ds-a72024_firmware
  • ds-a72072r_firmware
  • ds-a71048r-cvs_firmware
  • ds-a82024d
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control