CVE-2023-28814: Malicious File Upload
Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers may upload malicious files to the server. iSecure Center is software released for China's domestic market only, with no overseas release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28814?
CVE-2023-28814 has a high severity rating due to its potential to allow attackers to upload malicious files.
How do I fix CVE-2023-28814?
To mitigate CVE-2023-28814, ensure you implement proper file type validation and restrict file uploads to only allowed types.
Which versions of iSecure Center are affected by CVE-2023-28814?
CVE-2023-28814 affects certain versions of Hikvision's iSecure Center software released for the domestic market.
What type of vulnerability is CVE-2023-28814?
CVE-2023-28814 is classified as an improper file upload control vulnerability.
Who is primarily affected by CVE-2023-28814?
Users of Hikvision's iSecure Center software in China's domestic market are primarily affected by CVE-2023-28814.