Impact
Some Hikvision intercom products incorporate an immutable factory value that should be retrieved from the local network or through physical interaction with the device’s main card. An attacker can acquire this value and use it to forge a legitimate main card, thereby gaining permission to issue cards and authenticate as an authorized user. This vulnerability, associated with CWE-1310 and CWE-798, allows the creation of counterfeit authentication tokens, enabling an attacker to gain unauthorized access to the intercom system and any premises secured by it.
Affected Systems
The affected products are Hikvision intercom devices: DS-KD8003, DS-KD8005, DS-KV6103, DS-KV6113, DS-KV6114, DS-KV6124, DS-KV6133, DS-KV6134, DS-KV8113, DS-KV8114, DS-KV8213, DS-KV8413, and DS-KV9503. No specific firmware or hardware revision details are provided, so any current production unit of these models may be susceptible.
Risk and Exploitability
The CVSS score of 6.1 classifies this issue as moderate. EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote or local network‑based, as forging M1 cards requires interaction with the intercom’s authentication interface. An attacker could generate a valid card credential, thereby bypassing normal access controls. The potential impact ranges from unauthorized entry into protected areas to exploitation of the intercom’s control functions.
OpenCVE Enrichment