Vulnerability record · CVE-2023-6893 · published 17 December 2023
CVE-2023-6893: Hikvision Intercom Broadcasting System path traversal in exportrecord.php
Hikvision · Intercom Broadcast System
Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains a path traversal flaw in /php/exportrecord.php where the downname argument is not properly sanitized. An unauthenticated remote attacker can manipulate downname to read arbitrary files on the server. The issue is fixed in version 4.1.0.
Description
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input C:\ICPAS\Wnmp\WWW\php\conversion.php leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248252.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication, has a public exploit, and a high EPSS score, though it is not known to be actively exploited in ransomware campaigns.
What it is
Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) contains a path traversal flaw in /php/exportrecord.php where the downname argument is not properly sanitized. An unauthenticated remote attacker can manipulate downname to read arbitrary files on the server. The issue is fixed in version 4.1.0.
Impact
An attacker can read arbitrary files on the affected system, potentially exposing configuration data, credentials, or other sensitive information. There is no impact to integrity or availability per the CVSS vector.
Attack surface
The vulnerability is reachable over the network via HTTP requests to /php/exportrecord.php. No authentication or user interaction is required according to the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
A public exploit has been disclosed and may be used, as indicated by the Exploit tag on the GitHub reference. The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation activity (0.70224, 99.348th percentile).
What to do
- Upgrade Hikvision Intercom Broadcasting System to version 4.1.0 or later.
- If immediate upgrade is not possible, restrict network access to the web interface of the affected system to trusted networks only.
- Validate and sanitize the downname parameter to prevent path traversal sequences.
- Monitor for and block requests containing path traversal patterns targeting /php/exportrecord.php.
Detection
- Inspect web server logs for requests to /php/exportrecord.php with downname parameters containing traversal sequences such as ../ or ..\.
- Monitor for anomalous file read attempts or access to sensitive files outside the web root.
- Use network detection to flag HTTP requests with encoded traversal patterns in the downname parameter.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/willchen0011/cve/blob/main/download.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.248252 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.248252 | Third Party Advisory |
| https://github.com/willchen0011/cve/blob/main/download.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.248252 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.248252 | Third Party Advisory |
Track CVE-2023-6893 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6893), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.