Axis Hides Exploit Danger

By: John Honovich, Published on Aug 09, 2016

Axis is hiding the severity and danger of the 'remote string format' vulnerability.

We ask Axis to fully communicate the risks of the released 'Hack Axis' program to Axis users and urge everyone with Axis devices to upgrade them immediately. 

Exploit Danger

The danger is that a working 'Hack Axis' program was released 3 weeks ago. This programs allows:

  • Root access to Axis devices, without having to know or figure out the password (regardless of how hard the password is).
  • Changing the Axis web password, with a simple additional command, to get full control of video and configuration
  • Turning Axis devices into botnets to attack computers throughout the world.
  • Hijacking Axis devices that continues even after they are upgraded to 'fix' the exploit and even after a factory reset, allowing continued malicious access and control. This was tested with a researcher who did this to an IPVM Axis device, which we verified. 

Axis stresses the main 'limitation' is that one needs network access to the camera, which is true, but undermines that mistakes can occur that allow devices to be remotely accessible and that many contractors, including competitors, often have access to internal systems. And, of course, the tens of thousands of Axis devices made publicly available are extremely at risk.

Axis Communications Failure

Axis has never communicated that a working 'Hack Axis' program has been released and shared across Internet hacking sites. It is now 3 weeks since this was done and Axis has done nothing to communicate that or correct their existing erroneous communications.

(1) The Axis FAQ on this issue declares:

[Update Aug 12th: Axis has edited the FAQ to remove this claim.]

Get Notified of Video Surveillance Breaking News
Get Notified of Video Surveillance Breaking News

But the vulnerability has been disclosed and is widely known and available on many cybersecurity / hacking sites, including the Exploit Database.

(2) The Axis corporate press release states:

 

Unfortunately for Axis users, Axis has not updated that release nor issued any subsequent release making it clear that not only it is disclosed but the working program allowing for exploitation is released.

(3) Axis has a CVE report which at least mentions the appropriate term exploit:

Three weeks after it was disclosed, Axis still has not updated this.

[Update Aug 12th: 24 days after the disclosure Axis has issued a new CVE report where they acknowledge the full exploit and the available Python script.]

In sum, Axis, after initial limited announcement and no communication about a full working program being released, is now completely ignoring the issue. We emailed Axis management multiple times about these concerns in addition to previous posts that raised them, without any action from Axis.

Axis Take Responsibility

Axis, please immediately fix all of your documentation and then issue a new release and email blasts explaining that a working Hack Axis program does exist and is widely available for hackers and your competitors to take advantage.

Exploits happen to everyone. We agree with Axis engineering team that this was a very hard / obscure exploit to find. That it happened should not be a black eye for Axis.

Axis is great at communication... when they want to. But how Axis has (not) communicated this is inappropriate, leaving Axis partners and customers at significant risk. Axis certainly wants to be a leader in cybersecurity. This exploit should not undermine that. But failing to properly inform your users of the full risk absolutely should.

1 report cite this report:

Dahua Distributor Angered "Always Give Good News About Hikvision" on Aug 11, 2016
A Dahua distributor is angry that "IPVM always give good news about HIKvision while destroys Dahua." I can understand the frustration, not of...
Comments (6) : Members only. Login. or Join.

Related Reports

Verint Victimized By Ransomware on Apr 18, 2019
Verint, which is best known in the physical security industry for video surveillance but has built a sizeable cybersecurity business as well, was...
Security Fail: ASISNYC Auto Emails Passwords In Plain Text on May 14, 2019
ASIS NYC automatically emails a user with the password the user just entered, in plain text, when one registers for the site / event, as the...
LifeSafety Power NetLink Vulnerabilities And Problematic Response on May 20, 2019
'Power supplies' are not devices that many think about when considering vulnerabilities but as more and more devices go 'online', the risks for...
Honeywell Speaks On NDAA Ban, New Non-Banned Cameras and Cybersecurity on Aug 06, 2019
For years, Honeywell has depended on Dahua, a company with a poor cybersecurity track record and now banned by the US NDAA, for the development and...
Dahua Wiretapping Vulnerability on Aug 02, 2019
IPVM has validated, with testing, and from Dahua, that many Dahua cameras have a wiretapping vulnerability. Even if the camera's audio has been...
Uniview OEM Directory on Sep 11, 2019
This directory lists 20+ companies that OEM products from Uniview, with a graphic and links to company websites below. It does not cover all...
Warning: Windows 7 Update Crashing NVRs on Aug 26, 2019
Windows 7 updates are causing VMS servers to fail to boot. After running the update, impacted systems do not boot as normal, instead display this...
Mobotix First CNPP CCTV Cybersecurity Certification Examined on Sep 05, 2019
Mobotix recently became the first video surveillance manufacturer to receive the CNPP cybsersecurity certification for its cameras, in which they...
ONVIF Exposure To "Devastating DDoS Attacks" Examined on Sep 06, 2019
ZDnet reported "Protocol used by 630,000 devices can be abused for devastating DDoS attacks", citing exposure of ONVIF devices. And after an...
Dahua New Critical Vulnerability 2019 on Sep 23, 2019
Dahua has quietly admitted 5 new vulnerabilities including 1 critical vulnerability with a 9.8 / 10.0 CVSS score and 2 high vulnerabilities (scored...

Most Recent Industry Reports

Motorola / Avigilon Drops ISC West on Feb 26, 2020
Motorola Solutions has pulled out of ISC West 2020 effective immediately, because of coronavirus concerns, IPVM has learned. This is done amidst...
Cancel or Not? Industry Split Over ISC West on Feb 26, 2020
The industry is split, polarized, over whether ISC West 2020 should run or be canceled. New IPVM survey results of 400+ respondents show heated...
Coronavirus Hits Sony, Bosch Says Switch on Feb 26, 2020
Sony's fall in video surveillance has been severe over the past decade. Now, they may be done. In this note, we examine Bosch's new...
Video Surveillance Cameras 101 on Feb 25, 2020
Cameras come in many shapes, sizes and specifications. This 101 examines the basics of cameras and features used in 2020. In this report, we...
Favorite Video Analytic Manufacturers 2020 on Feb 25, 2020
Video analytics is now as hot as ever, driven by the excitement of advancing deep learning offers. But what are actually integrator's...
Latest London Police Facial Recognition Suffers Serious Issues on Feb 24, 2020
On February 20, IPVM visited another live face rec deployment by London police, but this time the system was thwarted by technical problems and...
Masks Cause Major Facial Recognition Problems on Feb 24, 2020
Coronavirus is spurring an increase in the use of medical masks, which new IPVM test results show cause major problems for facial recognition...
Every VMS Will Become a VSaaS on Feb 21, 2020
VMS is ending. Soon every VMS will be a VSaaS. Competitive dynamics will be redrawn. What does this mean? VMS Historically...
Video Surveillance 101 Course - Last Chance on Feb 20, 2020
This is the last chance to join IPVM's first Video Surveillance 101 course, designed to help those new to the industry to quickly understand the...
Vulnerability Directory For Access Credentials on Feb 20, 2020
Knowing which access credentials are insecure can be difficult to see, especially because most look and feel the same. Even insecure 125 kHz...