cbcvebase.
CVE-2023-28809
published 2023-06-15

CVE-2023-28809: Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in…

PriorityP341high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.64%
45.9th percentile
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.

Affected

6 ranges
VendorProductVersion rangeFixed in
hikvisionds-k1t320xxx>= V3.5.0_build220706 < V3.5.0_build220706V3.5.0_build220706
hikvisionds-k1t341axx>= V3.2.30_build221223 < V3.2.30_build221223V3.2.30_build221223
hikvisionds-k1t341c>= V3.3.8_build230112 < V3.3.8_build230112V3.3.8_build230112
hikvisionds-k1t343xxx>= V3.14.0_build230117 < V3.14.0_build230117V3.14.0_build230117
hikvisionds-k1t671xxx>= V3.2.30_build221223 < V3.2.30_build221223V3.2.30_build221223
hikvisionds-k1t804axx>= V1.4.0_build221212 < V1.4.0_build221212V1.4.0_build221212
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.