CVE-2023-28808: Critical severity hikvision ds-a71024 vulnerability
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-28808?
CVE-2023-28808 is a vulnerability in some Hikvision Hybrid SAN/Cluster Storage products that allows an attacker to obtain admin permissions.
How can the vulnerability in Hikvision Hybrid SAN/Cluster Storage products be exploited?
The vulnerability can be exploited by sending crafted messages to the affected devices.
What is the severity of CVE-2023-28808?
The severity of CVE-2023-28808 is critical, with a CVSS score of 9.8.
Which Hikvision Hybrid SAN/Cluster Storage products are affected by CVE-2023-28808?
Some Hikvision Hybrid SAN/Cluster Storage products with the following firmware versions are affected: DS-a71024, DS-a71048, DS-a71072r, DS-a80624s, DS-a81016s, DS-a72024, DS-a72072r, DS-a80316s, DS-a82024d.
How can I fix CVE-2023-28808?
To fix CVE-2023-28808, update the firmware of the affected Hikvision Hybrid SAN/Cluster Storage products to version 2.3.8-8 or later.