High severity7.5NVD Advisory· Published Jun 15, 2023· Updated Jun 17, 2026
CVE-2023-28809
CVE-2023-28809
Description
Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.
Affected products
33- cpe:2.3:o:hikvision:ds-k1t320efwx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320efx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320ewx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320ex_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320mfwx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320mfx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320mwx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t320mx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t341am_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t341amf_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t341cm_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t343ewx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t343ex_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t343mwx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t343mx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671m_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671mf_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671t_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671tm-3xf_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671tm_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671tmf_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671tmfw_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t671tmw_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t804af_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:hikvision:ds-k1t804amf_firmware:-:*:*:*:*:*:*:*
- hikvision/DS-K1T320XXXv5Range: V3.5.0_build220706
- hikvision/DS-K1T341AXXv5Range: V3.2.30_build221223
- Range: V3.3.8_build230112
- hikvision/DS-K1T343XXXv5Range: V3.14.0_build230117
- hikvision/DS-K1T671XXXv5Range: V3.2.30_build221223
- hikvision/DS-K1T804AXXv5Range: V1.4.0_build221212
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.