First published: Sun Dec 17 2023(Updated: )
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input C:\ICPAS\Wnmp\WWW\php\conversion.php leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248252.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Hikvision Intercom Broadcast System | >=3.0.3<4.1.0 | |
Any of | ||
Hikvision DS-KD-BK | ||
Hikvision DS-KD-DIS | ||
Hikvision DS-KD-E | ||
Hikvision DS-KD-IN | ||
Hikvision DS-KD-INFO | ||
Hikvision DS-KD-KK | ||
Hikvision DS-KD-KK/S | ||
Hikvision DS-KD-KP | ||
Hikvision DS-KD-KP/S | ||
Hikvision DS-KD-M | ||
Hikvision DS-KD3003-E6 | ||
Hikvision DS-KD8003IME1(B) | ||
Hikvision DS-KD8003IME1(B) | ||
Hikvision DS-KD8003IME1(B)/NS | ||
Hikvision DS-KD8003IME1(B)/S | ||
Hikvision DS-KD8003IME1(B)/SURFACE | ||
Hikvision DS-KH6220-LE1 Firmware | ||
Hikvision DS-KH6320 | ||
Hikvision DS-KH6320 | ||
Hikvision DS-KH6320 | ||
Hikvision DS-KH6320 | ||
Hikvision DS-KH6320 | ||
Hikvision DS-KH6350-WTE1 Firmware | ||
Hikvision DS-KH6351-TE1 Firmware | ||
Hikvision DS-KH6351-TE1 | ||
Hikvision DS-KH63LE1(B) | ||
Hikvision DS-KH8520-WTE1 | ||
Hikvision DS-KH9310-WTE1(B) | ||
Hikvision DS-KH9510-WTE1(B) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6893 is classified as a problematic vulnerability affecting Hikvision Intercom Broadcasting System.
To fix CVE-2023-6893, upgrading to version 4.1.0 or later of the Hikvision Intercom Broadcasting System is recommended.
CVE-2023-6893 affects the Hikvision Intercom Broadcasting System versions 3.0.3 to 4.1.0.
CVE-2023-6893 involves manipulation of input parameters in the file /php/exportrecord.php.
As of now, there have been no publicly disclosed exploits specifically targeting CVE-2023-6893.