Vulnerability Description
There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hikvision | Nvr-216Mh-C\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-216Mh-C\(D\) | - |
| Hikvision | Nvr-216Mh-C\/16P\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-216Mh-C\/16P\(D\) | - |
| Hikvision | Nvr-208Mh-C\/8P\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-208Mh-C\/8P\(D\) | - |
| Hikvision | Nvr-104Mh-C\/4P\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-104Mh-C\/4P\(D\) | - |
| Hikvision | Nvr-104Mh-C\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-104Mh-C\(D\) | - |
| Hikvision | Nvr-108Mh-C\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-108Mh-C\(D\) | - |
| Hikvision | Nvr-116Mh-C\(D\) Firmware | < 4.1.60 |
| Hikvision | Nvr-116Mh-C\(D\) | - |
| Hikvision | Ds-7104Ni-Q1\(C\) Firmware | < 4.1.60 |
| Hikvision | Ds-7104Ni-Q1\(C\) | - |
| Hikvision | Ds-7104Ni-Q1\(D\) Firmware | < 4.1.60 |
| Hikvision | Ds-7104Ni-Q1\(D\) | - |
| Hikvision | Ds-7108Ni-Q1\(C\) Firmware | < 4.1.60 |
| Hikvision | Ds-7108Ni-Q1\(C\) | - |
Related Weaknesses (CWE)
References
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/buffer-overPatchVendor Advisory
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/buffer-overPatchVendor Advisory
FAQ
What is CVE-2023-28811?
CVE-2023-28811 is a vulnerability with a CVSS score of 7.4 (HIGH). There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending...
How severe is CVE-2023-28811?
CVE-2023-28811 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28811?
Check the references section above for vendor advisories and patch information. Affected products include: Hikvision Nvr-216Mh-C\(D\) Firmware, Hikvision Nvr-216Mh-C\(D\), Hikvision Nvr-216Mh-C\/16P\(D\) Firmware, Hikvision Nvr-216Mh-C\/16P\(D\), Hikvision Nvr-208Mh-C\/8P\(D\) Firmware.