CVE-2023-28809
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-384
- Affected
- hikvision/ds-k1t320efwx firmware · hikvision/ds-k1t320efx firmware · hikvision/ds-k1t320ewx firmware · hikvision/ds-k1t320ex firmware · hikvision/ds-k1t320mfwx firmware · hikvision/ds-k1t320mfx firmware · hikvision/ds-k1t320mwx firmware · hikvision/ds-k1t320mx firmware · hikvision/ds-k1t341am firmware · hikvision/ds-k1t341amf firmware · hikvision/ds-k1t341cm firmware · hikvision/ds-k1t343ewx firmware · hikvision/ds-k1t343ex firmware · hikvision/ds-k1t343mwx firmware · hikvision/ds-k1t343mx firmware · hikvision/ds-k1t671 firmware · hikvision/ds-k1t671m firmware · hikvision/ds-k1t671mf firmware · hikvision/ds-k1t671t firmware · hikvision/ds-k1t671tm firmware · +6 more
- Source
- hsrc@hikvision.com
References
- http://packetstormsecurity.com/files/174506/Hikvision-Access-Control-Session-Hijacking.html
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-access-control-intercom/Vendor Advisory
- http://packetstormsecurity.com/files/174506/Hikvision-Access-Control-Session-Hijacking.html
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-access-control-intercom/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.