Dahua Critical Cloud Vulnerabilities

Published May 12, 2020 16:14 PM

Dahua has acknowledged a series of cloud vulnerabilities that researcher Bashis discovered. Additionally, and separately, researcher Thomas Vogt found a separate vulnerability.

IPVM Image

Dahua has had numerous vulnerabilities over the past few years including the 2019 critical vulnerabilities that Vogt's team found and the 2017 backdoor that Bashis found. The company is moreover banned for US federal use (NDAA) based on cybersecurity risks.

Inside this report:

  • A summary of the vulnerabilities
  • The vulnerabilities explained
  • A statement from Dahua
  • OEMs Impacted
  • Response from bashis
  • Analysis from Refirm Labs
  • Continued cybersecurity issues
  • IPVM recommendations

Long **** *************** *** *****

***** *** ****** **** ********* **** Dahua *** *** (*********) ***** ***** issues, *******, **** ******* *** * long ****, ************ ***** ****** * ******* ** this ** **** ** ********:

IPVM Image

********, ****** *** **** ** **** that **** ***** ******* **** *** cloud ****:

****, **’* *** ** **** ** just ****** ***** **** ** *** devices ****** *** *****, ** **** will **** *** **** **** ***** ** *** ***** ******* ***.

****** **** ********* ***** ********* *****:

******* ** **** ******* **** ** connected *** ********** ** *** ***** by *** *******, **** ** ****** has ********** **** ** ***** *** account.

**, **** ** *******,

*) ***** *** ****** ** ******* **** **** ****** ***** **** that ***?

*) ****** **** ***** ***** **** ownership ** **** *** ******** ** their ******* (******** **** * ***** above ***** ********).

*** ******** ********:

  • ***** *** ** ****, ********* ********* and *******, ***** ***** ***** ******** were **********.
  • ***** ********* *** ***** ****/********* *** all **** (********* ********* *** *******) then ******** *** **** ** ** executable **** *** *********** ** ***.
  • ********* ***** *** ***** ***** **** to ******* *********** ***** * ******* listening ****** ** ******* **********.
  • ***** **** ***/**** ** ******* ********* / ***** ******** ********* ******* ** a ****** ******** **** ***.
  • ***** *** ******* ****** ** ******** and ***** ********* ***** ******.
  • ********* ***** **** **** ****** ** equipment *** ***** ****** ** ******* by ******* ** *** ***** ********.

Dahua ***** ************* *********

****** ****** * ***** ** ******* for *** ***************. *****'* ***** ******** ** **** for ***** ******* ********* ** **** as ** **** *** *** ********* cloud **** ****** ****** ** ********** that *** *********** ** ***** *** available *** ******** *** *** ***.

***** *************** ****** ********* ** **** full ****** ** *** ********* *********.

*** ***** ************* ****** ** *********** being ****** *** *** ***** ******, which ********* *** ****** *** ***** 8 ********** ** *********. ***** *** two ******* *************** ********* **** ******* with ********* ******* ** ******* *** data.

*** ***** ************* ** * ****-********** file ** *** ***** ******** **** IMOU ***** ********* ***** ****/******** *** other ******* ******* *** ***** *** 22 ****.

Statement **** *****

********** ****** * ******** ******** ************** ** *** ***************, **** *** not ****** *** ********* ***** *** they **** ** **** ***** ******* vulnerabilities. **** *** *****, **** **** made ******* *******, ********* **** ** 2017, ***** *** ********,******:

“************** **** ******* **** * ***** source ** ********** *** ***********, ********** and *********** *****-****,” ********* **. ******, Head ** *********, ***** *******, ***** Technology ***. “** ********* ** *** development ** ******** ************* *********** *** new ******* ******** **** ****** ********** to *****-*******, *****’* ******* **** **** to ****** ******* ***** ********* ******* cyber ******* *** **** ******* ****** protection *** *** ****** ****** ********* community.”

OEM's ********

***** *** ** **** ****** ******* notables **** ********* *** *******. **** reached *** ** ********* *** *******.

***** ** * ********** **** *** PoC ******* *** ***** **** *** Panasonic, *******, *** ******:

IPVM Image

********* ********* ******* **** **** **** continue ** ******** **** *** ****** if ***** *** **** ** ***** customers.

Refirm **** ********

************* ******* ****** ************ *** *************** *** ******** ** IPVM *********:

*** *** **** ***** ** ***** it *** *********** *** ********* **** either *** ** **** **** **** in *** *****. *** ****** *** Unix-like ******* *** *** ******** ** the *** ** ******** *** **** so *** ******** ****** ** (******) reversed. ***** ** ***** ********* ***/**** keys ** ******* *** ******** ******** on *** ***** ****. **** ** bad *** **** ******* *** ********* if ** ******** ***** *** ********* key *** *** ********* ******* *** network ******* *** ***** ** **** to ********* ******* *** *********** ** the ****. *** ******* ***** **** a ******* ********* ****** ** ******* the ******** *** ******* ********** ***** also ****.

**** ** *** ***** **** ***** the ****. ***** *** ********** *** of ***** ***** **** "*****" ***/**** keys ** ***** ********** **** *** being ***********. **** ********. ** ***** let *** **** ****** ***** *** password *** ****** ** **********? * cannot ***** ** * ********* ****** to ** ****.

** *** *** **** ** *** Dahua ***** **** *** *** *********** remotely ******* *** ****** ********* ** it.

**** ************ ***** **** ** ***** cyber ******** **** *********. *********** ****** always ** ********* ** ** ******** accepted ****** ******** (*.*. ***), ********* keys ****** ***** ** **** ** protect ************** ****, *** ** *** do *** ******** **** ***'* ******* them *** ** * ****** ********** that *** ******* ** *** *****.

Another ***** *** **** *************

***** *********** *** *************** ***** ** were******** ** *** ******* ***** ************************* ****** ****:

IPVM Image

***** *** ****** ********* ******** ***** **** ****, ******:

**** ***** ******** **** ******* ** predictable ***************. ****** ****** **** ******, an ******** *** *** *** ********* Session ** ** ********* * **** packet ** ****** *** ******.

* ******* ** ****** *** ******** is ********, ********* ******** ** ********* the *************.

Continued ************* ******

***** *** **** *** **** ****** vulnerabilities. ***** *** * **** ******* of ************* *************** ***** *** ** them *********** *** *** **** *** ** government *** ** ********** ****** *********. ***** ****** *************** ******* *** are *** ******* ** *** **** below:

What ***** ******?

** ****** ****,***** *** ****** ********* **** **** would ** "******-**", ********* * *************, ******, *** featured ***** ******** *** ****** ****** cloud ********. *** ******* **** **** both *** ** ***** **** **** which ** *********** ** *** ************* findings ** * ***** ** ******* and *** ************ ** ****. **** contacted ***** *** ****** *** ** update. ******* ** ***** * ****** since *** ***** ******* ***** ** no ******** ** ***** **. ***** has *** ********* ** *** ******* and ****** ********* ****:

***** ******** **********, ** ** *** have ******* ** *** **** ******* to ***** ** **** ****.

IPVM ***************

** *** *** ***** ***** ** Dahua *** ********* *** ****** ***** to ****** **** ***** ****** ** disabled. ***** ******* **** ** *******, so **** ** *** *** *** actively ***** ***** ***** ******** ********* can ***** **** ****** ** **** equipment ****** *** ******* **. ** you *** ******** ***** *** ***** solution *** *** ******** ****** ** a **** ************ ****** ****** **** ***.

Poll / ****

Comments (10)
UI
Undisclosed Integrator #1
May 12, 2020

** ******* *** *** ***** ******** to ***** ****** ****** **********? * don't ********** *** *** ***** ***** be ******* ** ******* !?

JH
John Honovich
May 12, 2020
IPVM

**, ****** ****** * ****** ***** he *** * **** ** *****. And **** *** ** *** ** the ***** ** **** ** *** a ******** **** *****.

(2)
UI
Undisclosed Integrator #1
May 12, 2020

** ****... **** ** * **** poor **** **** ***** :(

UM
Undisclosed Manufacturer #2
May 12, 2020

***** *** ********** *** ** ***** major **** "*****" ***/**** **** ** their ********** **** *** ***** ***********. Just ********. ** ***** *** *** OEMs ****** ***** *** ******** *** secure ** **********? * ****** ***** of * ********* ****** ** ** this.

**** ** *** **** ****** ***** to **. **'* *** ***** ** their ***** **** *** *********** ***** things **** ******** *** ******* *** and **** ******* ********** ***** ** bad *** **************, *** ********** *** encryption **** ** *** ********** *** all ***** ********* *** ***** **** and ***** **** ** ********** ** terms ** ********.

*****'* ***** ******** ** **** *** Dahua ******* ********* ** **** ** 22 **** *** *** ********* ***** keys ****** ****** ** ********** **** was *********** ** ***** *** ********* for ******** *** *** ***.

** ***** ** *** ** **** only *********** *** ********** **** *** keys ********** ** *****, *** **'* a *********** **** ***** *********** **** been *** ** *** ****** **** the ********** ****.

****:** **** ********* ** **** **** of *** **** *** *** * requirement **** **** **** ** *** a ********** *** **** **** **** generated ********** ****** **** *** **** was ******** ** ****. *'* ****** that ******* *** *** ** *** system *** *** **** ***** **** realized **** **** *** **** ** strange, ** ***** ***** *** ** the ***** ******** *** ****?

UM
Undisclosed Manufacturer #4
May 13, 2020

* ***** ****** ** *** *******, that ***** ****** *** ** *** cloud *** *** ****. ** ***** they ***'* **** *** ** *** it ** ******* ** *** ******** and **** **** *********** **.

*** ****** *** *** **** ** security ** **** ** ** ****. That ** *** *** ** ***** companies ** ** ** ***.

(1)
bm
bashis mcw
May 13, 2020

*** ******, *** *** ***** *** Cloud **** *** ***** **/**** ** their *****. (** *** *** **** exposed *****/**** **/****, * ***** ***'* IP/FQDN ** **** ********** ***, *** didn't **** ** ********* ** ****** them ** *** *** ***********, *** cloud **** ***** ******)

**** ** ***** ** **** ********** leaks *** ***** *** *****, *** - **** ***** **** ***.

****:

**** *** ********* *** *** ****** the ******, ** ******** ******** **** the ***** ****** (*******/*******) ***** **** PSK, ****** ******* ***** *** **** needs ** ******* *** ***** **** need ** ******* - *** *** thing ** **** ***** *********** *** sent ** ****** *** ********** *****/****** for *****/*****, *** *** **** ***** login **** ****.

* *** ** ****** ** ******* ***** ******* ********** **** ***** ** ****, (******* w/o ********** *****), *** ** ***** you *** *** **** *** ** you ****.

(2)
UI
Undisclosed Integrator #3
May 13, 2020

*****'* **** *** **** *** ****. It *** **** ****** ***** ****** cameras **** ****, *** *** **** we *** **** ** *** ******** it ** ***** ****** ** *** them. ** *** **** *** ***** for *** ***** *****.

**** ** *******, *** ****** ***** your *** ****** ********** *** ******** before *** ******. **** * ******* security ************ ****** *** ************** ****** you ** *******.

**** ******** *** ******** *******. *** how ***** ***?

Avatar
John Scanlan
May 13, 2020
IPVM • IPVMU Certified

******: **** ****** *** **** ******* to ******* ****,******* ** ***** * months ***** *** ***** *******, ***** is ** ******** ** ***** ** with ******* ** *** ***** / Pepper ************. ***** *** *** ********* to *** ******* *** ****** ********* stating:

***** ******** **********, ** ** *** have ******* ** *** **** ******* to ***** ** **** ****.

Avatar
Jon Dillabaugh
May 15, 2020
Pro Focus LLC

*** **** ****** ****** ****** ** the **** ***** *** ***** ***** guys. **** ***** ***** ***** **** WEAK. *** ****** ***** **** **** AVERAGE. 🤣

UD
Undisclosed Distributor #5
May 17, 2020

***, *** ******** ***** ****.