CVE-2023-28808
Summary
| CVE | CVE-2023-28808 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-11 21:15:00 UTC |
| Updated | 2023-04-24 13:50:00 UTC |
| Description | Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hikvision | Ds-a71024 | - | All | All | All |
| Operating System | Hikvision | Ds-a71024 Firmware | All | All | All | All |
| Operating System | Hikvision | Ds-a71024 Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a71048 | - | All | All | All |
| Hardware | Hikvision | Ds-a71048r-cvs | - | All | All | All |
| Operating System | Hikvision | Ds-a71048r-cvs Firmware | All | All | All | All |
| Operating System | Hikvision | Ds-a71048 Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a71072r | - | All | All | All |
| Operating System | Hikvision | Ds-a71072r Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a72024 | - | All | All | All |
| Operating System | Hikvision | Ds-a72024 Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a72072r | - | All | All | All |
| Operating System | Hikvision | Ds-a72072r Firmware | - | All | All | All |
| Operating System | Hikvision | Ds-a72072r Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a80316s | - | All | All | All |
| Operating System | Hikvision | Ds-a80316s Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a80624s | - | All | All | All |
| Operating System | Hikvision | Ds-a80624s Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a81016s | - | All | All | All |
| Operating System | Hikvision | Ds-a81016s Firmware | All | All | All | All |
| Hardware | Hikvision | Ds-a82024d | - | All | All | All |
| Operating System | Hikvision | Ds-a82024d Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Vulnerability in Some Hikvision Hybrid SAN/Cluster Storage Products - Security Advisory - Hikvision | MISC | www.hikvision.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Souvik Kandar, Arko Dhar
There are currently no legacy QID mappings associated with this CVE.