Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-28809
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Hikvision Access Control Products 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hikvision DS-K1T和Hikvision DS-KH都是中国海康威视(Hikvision)公司的一系列门禁系统。 Hikvision Access Control Products存在安全漏洞,该漏洞源于用户登录成功后不会更新会话ID,导致易受到会话劫持攻击。以下产品及版本受到影响:Hikvision DS-K1T,Hikvision DS-KH。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
hikvisionDS-K1T804AXX V1.4.0_build221212 ~ V1.4.0_build221212 -
hikvisionDS-K1T341AXX V3.2.30_build221223 ~ V3.2.30_build221223 -
hikvisionDS-K1T671XXX V3.2.30_build221223 ~ V3.2.30_build221223 -
hikvisionDS-K1T343XXX V3.14.0_build230117 ~ V3.14.0_build230117 -
hikvisionDS-K1T341C V3.3.8_build230112 ~ V3.3.8_build230112 -
hikvisionDS-K1T320XXX V3.5.0_build220706 ~ V3.5.0_build220706 -
II. Public POCs for CVE-2023-28809
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-28809
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-28809

No comments yet


Leave a comment