SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-28810

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities.

MEDIUM 4.3EPSS 10.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.

Description

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
10.40% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
hikvision/ds-k1t804af firmware · hikvision/ds-k1t804amf firmware · hikvision/ds-k1t341am firmware · hikvision/ds-k1t341amf firmware · hikvision/ds-k1t671m firmware · hikvision/ds-k1t671mf firmware · hikvision/ds-k1t671 firmware · hikvision/ds-k1t343efwx firmware · hikvision/ds-k1t343efx firmware · hikvision/ds-k1t343ewx firmware · hikvision/ds-k1t343ex firmware · hikvision/ds-k1t343mfwx firmware · hikvision/ds-k1t343mfx firmware · hikvision/ds-k1t343mwx firmware · hikvision/ds-k1t343mx firmware · hikvision/ds-k1t341c firmware · hikvision/ds-k1t320efwx firmware · hikvision/ds-k1t320efx firmware · hikvision/ds-k1t320ewx firmware · hikvision/ds-k1t320ex firmware · +17 more
Source
hsrc@hikvision.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.