CVE-2023-28809
CVE-2023-28809
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Produtos afetados
hikvision · DS-K1T320XXXhikvision · DS-K1T341AXXhikvision · DS-K1T341Chikvision · DS-K1T343XXXhikvision · DS-K1T671XXXhikvision · DS-K1T804AXXQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →