CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-28812

CVSS 9.1v3.1pub. 2023-11-23upd. 2024-11-21

There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability by sending crafted messages to computers installed with this plug-in, which could lead to arbitrary code execution or cause process exception of the plug-in.

🤖 AI Analysis
How it works

The vulnerability consists of a buffer overflow in the browser plugin code. An attacker sends specially crafted messages to a computer with the installed plugin, causing the memory buffer boundaries to be exceeded. As a result, it is possible to overwrite critical data structures in the process memory, leading to arbitrary code execution (RCE) or triggering an exception and plugin process crash.

Impact

An attacker can remotely execute arbitrary code on the victim's computer (RCE) or cause the browser plugin process to crash, resulting in loss of availability. The vulnerability also enables compromise of the confidentiality of data processed by the application.

Mitigation & patch

Security patches available from the vendor should be applied according to references — detailed information about updated plugin versions is available in the Hikvision security bulletin at the address indicated in the references.

Who is affected

Computers with the Hikvision LocalServiceComponents web browser plugin installed; specific versions indicated in the vendor's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Hikvision Localservicecomponents

    APP
    Hikvision
    ≤ 1.0.0.78
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2023-28813HIGH8.1same product

An attacker could exploit a vulnerability by sending crafted messages to computers installed with this plug-in...

CVE-2021-36260CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w serwerze WWW kamer Hikvision (nieautoryzowany RCE)

CVE-2017-7921CRITICAL9.8⚠ KEVPL ✓same vendor

Hikvision IP Camera — ominięcie uwierzytelnienia (Auth Bypass)

CVE-2023-28808CRITICAL9.1PL ✓same vendor

Podatność kontroli dostępu w Hikvision Hybrid SAN/Cluster Storage

CVE-2022-28173CRITICAL9.1PL ✓same vendor

Hikvision Wireless Bridge – podatność access control w serwerze web