Buffer Overflow Vulnerability in Hikvision NVR/DVR Devices
CVE-2023-28811

6.5MEDIUM

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
23 November 2023

What is CVE-2023-28811?

A buffer overflow vulnerability exists in the password recovery function of Hikvision NVR and DVR models. This security flaw enables potential attackers on the same local area network (LAN) to disrupt device operations by sending specially crafted packets to an affected device that has not been patched. This vulnerability highlights the importance of maintaining regular updates and security measures to safeguard networked devices from exploitation.

Affected Version(s)

DS-71XXHGH-K(S) Build date before 230821(Version before V4.1.60 are not affected)

DS-71XXHGH-M(C) Build date before 230821(Version before V4.1.60 are not affected)

DS-71xxNI-Q1(C) Build date before 230821(Version before V4.1.60 are not affected)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Szot @IOActive
.