ZeroHour

CVE-2023-28811

CVSS 3.1
6.5 medium
EPSS
<1%p33
Published
()
Modified
Description

There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

Vendors
hikvision
Products
nvr-216mh-c\(d\) firmware, nvr-216mh-c\/16p\(d\) firmware, nvr-208mh-c\/8p\(d\) firmware, nvr-104mh-c\/4p\(d\) firmware, nvr-104mh-c\(d\) firmware, nvr-108mh-c\(d\) firmware, nvr-116mh-c\(d\) firmware, ds-7104ni-q1\(c\) firmware, ds-7104ni-q1\(d\) firmware, ds-7108ni-q1\(c\) firmware, ds-7108ni-q1\(d\) firmware, nvr-104mh-d\(c\) firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.