CVE-2023-28809
CVE-2023-28809
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
hikvision · DS-K1T320XXXhikvision · DS-K1T341AXXhikvision · DS-K1T341Chikvision · DS-K1T343XXXhikvision · DS-K1T671XXXhikvision · DS-K1T804AXX¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →