PT-2023-2441 · Hikvision · Hikvision Hybrid San/Cluster Storage

Arko Dhar

+1

·

Published

2023-04-10

·

Updated

2023-04-24

·

CVE-2023-28808

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hikvision Hybrid SAN/Cluster Storage products (affected versions not specified)
Description The issue is related to access control errors in the software, allowing a remote attacker to exploit the vulnerability and gain administrator privileges. This can be achieved by sending crafted messages to the affected devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02226
CVE-2023-28808

Affected Products

Hikvision Hybrid San/Cluster Storage