Impact
The vulnerability is an improper encryption configuration that allows an attacker to forge M1 access cards. If a forged card is used, the intercom system may authenticate the attacker as an authorized user, enabling physical or logical access to the protected premises. This vulnerability arises from weak or incorrectly configured cryptographic settings, allowing the creation of counterfeit authentication tokens. It is associated with CWE-1310.
Affected Systems
The affected products are Hikvision intercom devices: DS-KD8003, DS-KD8005, DS-KV6103, DS-KV6113, DS-KV6114, DS-KV6124, DS-KV6133, DS-KV6134, DS-KV8113, DS-KV8114, DS-KV8213, DS-KV8413, and DS-KV9503. No specific firmware or hardware revision details are provided, so any current production unit of these models may be susceptible.
Risk and Exploitability
The CVSS score of 5.2 classifies this issue as moderate. EPSS data is unavailable, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector is inferred to be remote or local network‑based, as forging M1 cards requires interaction with the intercom’s authentication interface. An attacker who can send crafted authentication messages to the device could generate a valid card credential, thereby bypassing normal access controls. The potential impact ranges from unauthorized entry into protected areas to exploitation of the intercom’s control functions.
OpenCVE Enrichment