Axis Three Medium Vulnerabilities Disclosed

Published Oct 06, 2021 15:03 PM

Three medium-severity vulnerabilities have been discovered in Axis firmware by a cybersecurity researcher, affecting 300+ models.

IPVM Image

Inside this report:

  • A summary of the vulnerabilities and their severity
  • Explanation of privileges required to exploit
  • Devices and firmware versions impacted
  • Feedback from Axis on the vulnerabilities and Nozomi's research
  • How these vulnerabilities and Axis' response compare to Dahua and Hikvision

Three ***************/****** ****** ******

************* ********** **************** ***** ******** *************** ** **** firmware, *** ******** ****** ** *** "******" *****. *** ** ***** *************** ***** allow ** ****** ** ****** ********* code, *********** ************ *** ******/***, ******** attacks ******* ***** ******* ** *** network, ** ****** ********* **.

***** **** **** ** ***** ******** of ***** *************** *** ** ***** of ******* ** *********.

Axis *********

**** ******** * ******** ****** ** their************* ********** ******* ** **** ***. **** further ********* ** ** **** ******'* description ** ***** *************** *** ******** and **** **** ******* ******** ****** firmware *** **** ******* (********* *****).

******’* *********** ** ***** ***** ** accurate. ** **** ****** ******* ******** with ****** *** ******** **** **** their ******* ******** ****’* ******* ** the **** ********* ******** **** **** tested *** ******** *** **** **-******* devices. *** ********** ** **** ***** flaws ***’* **** *** *********** ****, and *** *** **** ******** *********** about *** ******** ******* ** **** security ********. ** **** ****, ******* are ******* *********.

Requires ************* **********

***** *** ***** ** ***** *************** may ***** *** ****** ** ** compromised ** ********, ********** *** ** these *************** ******** ************* **********, *.*., a **** **** ** ****** **** an **** ****** ** ****.

** ** ******** *** ********* ** exploit ***** *************** ******** ** ********** a **** ** ***** * ******** URL, ****** *** **** **** ** actively ****** **** *** *** ** of ** **** ******.

******* ***** *************** ******* ************* ********** or ******** ** ************* ** *******, they *** **** ******** **** ***** which ******* ** ************** ** *******, e.g.,****** **************** ***************.

All **** ******* ********

******'* ******* ********** ** ***** *************** was ********* **** ** ****' ***-************ Companion ***, *** **** ********* ** their ********** ** ** **** **** are ******* ** *** **** *******.

***** *************** ****** ******* ** *** Active ******** ***** (**.*) ** **** as ****-**** ******* ******, ***** ******** many ******* **** **** **** ************ (**** ********* ******* *** * ***** after ***).

**** **** **, *** **** *********, that ******* ******** *** **** ******* is ******* ********* *** ***** ******:

  • **** ** ****** ***** **.*
  • **** ** **** *** ***** *.**.*.*
  • **** ** **** *** ***** *.**.*.*
  • **** ** **** *** ***** *.**.*.*

******** ** ********* ******' ********* *** ** ********, **********, *** updated ** **** ********* ****** *******.

Nozomi ******** ********

****** ******** ** * ************************ ******** ****, ***** *** ********** other ************ ******** ***************, ********* ************* *** **** *************,***** *** ***************, ********** *** ***************.

****** ********* **** ** "***********" ********** the *******,******** ** ***** ****.

*** ****, *********** ****** ** *** Axis ********* ******* ****** ******** **** to ********** *** ******** *** ******** these *************** ***********.

Axis ********* ** "***********"/******** ***** ******** ****** **********

** ******** ** *** **** ************* respond ** ************* ***********, **** ******* Nozomi *** ******* ***** ********* ** them:

** ***** ****** ******** *** ***** research *** **** ************* ********** *** disclosure *******. **** ************** ******** *********** to ******* *** ******* *** ******** as ** ** *** ****** **** long-term *********** ***** ******** ** ******* through ************* *** ************.

**** *** **** ***** ** ***** updated ******** ***** ******* ***** ***************, including ******** *** **** ************ *******, with **** ******** ** *** **** Nozomi ******** ********* ***** **********.

Contrast ** *****/*********

****' ******** ** ****** *** *** speed *** ******* **** ***** **** released ******** ******* ** ******* ***** issues ** * ***** ******** ** recent *************** ********* ** ***** *** Hikvision *******.

** *** **** *******'* ****** ******** ***************, ***** *** ************ ** *** researcher, ******, ***** **** ********* ******** on *** ***************. **** ***** **********, it ******* ******* ** *** ******* have **** *******, *** **** **********, which **** *** ****.

******** ****************** *********** ********* ** **** ********** **** reporting ***** ******"******* ***** ** ********" *************. *******, ** *** *** *********** clear ***** ***** ****** ****** ******* firmware ** ***** ******** **** ******* for ***** *******, ****** ***** ** detail ** *** ************** ****** ********** ********** ********* *******.

Comments (25)
SD
Shannon Davis
Oct 06, 2021
IPVMU Certified

***** ******* *****!

(3)
bm
bashis mcw
Oct 07, 2021

**** *****, *** * ***** **** Axis *** **** ** **** ****, they *** ***** **** ** **** on ******** *************** **** ** ** well.

* ****** **** **** ******** "******, find ******** ******, ** **** ** know *** *** **", *** * think ****'* *** ** *** ****** why **** ***'* *******/**** ***** ********'* and **** ***** ****** *** **** SSH ****** **** **** ***** (*** not **** ****** "*********" ***** ** many ****** **). ** **, ** shows ***** ********** ** ***** ********.

**** **** *'** **** ** **** now, ****** ** ******* **** *** :)

(3)
(10)
RS
Robert Shih
Oct 07, 2021
Independent

**** ** **** ***** ***** ****:

"*** **** ***************! *** **** ***************! You *** **** ***************!"

(8)
JH
John Honovich
Oct 07, 2021
IPVM

* ** ******* *** ******* ** say "**** *** * *************** *** Hikvision **** *** * ** *** past *****, ** **** ***** ********* is ***** ***** **** ****** **** Axis."

***** ***** **** ** ************* ** the ******** ** ***************.

(10)
(12)
RS
Robert Shih
Oct 07, 2021
Independent

**'* ****** **** ***** *** ************ of ******* ********* *** *** ********** of *** ********* ** ***** ******** that ****** ** *** **** ***** of * ******* ** ***** ********.

** ******* *** *******, ********** ****** that *** ***** *** ****** ** copyright/patent ************ (**** ** **** **** you *** ******** *** ***** *** output "***** *****" ***********) *** *** account *** *** ***** ** ******* for *** ****. **** ** **** utilize ****** **** ****** ****, *****'* a ***** ********* *** ** ******** and ***** ********** **** ****.

U
Undisclosed #2
Oct 07, 2021
IPVMU Certified

** ******* *** *******, ********** ****** that *** ***** *** ****** ** copyright/patent ************ (**** ** **** **** you *** ******** *** ***** *** output "***** *****" ***********)…

**** *** *** **** ******* ***** here? **** ********** ****** ***** ********* or?

(3)
RS
Robert Shih
Oct 08, 2021
Independent

******* *****'* * *** * **** that's ******* ***********, ** **** ** you **** ** *** ******* **** that's ******* ******* *******, ** ***** already ** *********** ******* *** ******* it.

*** ***** **** **** *** ****** of **** ******** **** ** **** sections, *** ** ***** ***** *** have ** ** ** ** ******** different *** ******* ******* ******* *********** the **** ****** ********* ******* *** that ***** ** *********** *** *** to ***. **** ****** *** ** reinvent *** ***** *** ** ** a ********* ***, ******* * **** vulnerable ***, ****** *** **** ** pay ********* ** *** ****** *** wrote *** ***** ****.

(1)
U
Undisclosed #2
Oct 08, 2021
IPVMU Certified

******* *****'* * *** * **** that's ******* ***********, ** **** ** you **** ** *** ******* **** that's ******* ******* *******, ** ***** already ** *********** ******* *** ******* it.

*** ***** *** ** ** ********** of ******* ****’* *********** **** ******* knowing **?

(1)
UI
Undisclosed Integrator #3
Oct 08, 2021

*****. **** ****** **** **** * patent ******* **** * ********* ******* to **. ********* ** **** ** the ***** ** **********. ** ***** be **** ** *************** ******* * copyright ** ******* ****.

**** ** **** **** *** *** reinvent *** ***** *** ****** "***** World" ***********

** *****'* *** *** ** ** it, *****'* *** *** ** ** it... *** *******'* *** ***** ** think *****'* ********** ** ********* ****** print("Hello *****!") ** ****** *****, *** any ****** ***** ***** **** *******'* either.

**** ********* ********** ** *** ****** world ******** **** ** ** **** people **************** ***/****/***/***/***/** ** ********** ** provide *********** *** **** **** ***** Overflow (***'* ** ******, ********* ****** from ***** ********).

******* *** **** ** *** *****. You ***'* **** ** **** ********'* source **** ** **** ***** ****. And *** ***** *** **** **** mistakes ** *** ****. ** * recall, ******** ***** ** ****** ****** lists ****. *** *** ***** *** into **** **** ** ******* ** matter **** *********** *** **.

**** ******* ** ****** ******, ******, a *** ** ** ** ******** best *********, ********** ********** ** ***-****** organizations **** *****. **** ****, ***** is **** ** *** ** **********, publishes ***************. ** ***'** ********* ***** open-source **********, *** *******'* **** ** worry ***** ******* ** ****** **********. There's * *** ** ***** ****** following **** ** ****, *** ** you *** **** ** ****** ** easy ** *** ****. (** *** want ** ****** *** ******** ******** and *** *********'* ***** ********** *********™, then *** *** **** ** *** a ******* **** *********.)

** ******, **** ***** ****** ****.

RS
Robert Shih
Oct 08, 2021
Independent

*********** *** **** **** ******* *********. There's **** ******** ** ***** **** song *** **********. *** *** ********* end ** ******* ********* ******* ** someone ****'* **** ******* **** **** having **** ** *********** **** **** and ** *** **** *** ***** back ** ****** *** *** ***** you ** ******* ** **** ***** your *** **** ********.

* ***** *** **** ***** ********* also *******, *** ***** *** ******** issues ***** *********** *** **** ******* as ****.

(1)
(1)
U
Undisclosed #2
Oct 09, 2021
IPVMU Certified

*** ***** **** **** *** ****** of **** ******** **** ** **** sections, *** ** ***** ***** *** have ** ** ** ** ******** different *** ******* ******* ******* *********** the **** ****** ********* ******* *** that ***** ** *********** *** *** to ***. **** ****** *** ** reinvent *** ***** *** ** ** a ********* ***, ******* * **** vulnerable ***, ****** *** **** ** pay ********* ** *** ****** *** wrote *** ***** ****.

***** ***, *********** ****** ******* **** is *** ** * **** ********* or ***********, ** ** * ********* matter, ***** ** ** ********** *** someone ** **** **** * *****.

******, ***** **** ***** ** ******* source **** ***********, ********* ** ********* to ******* ******* ***** *** ********* cannot ** ***********, **** ****************** ** *** ****, *** **** only ** ***** *** ***** **** to ***** ******* *** **** *********.

** *****, *’* ****** ********* **** when ********** * ** *********** * begins ** ***** **** ********* **** scratch ** *****’* ***** **** * copyright ******.

*** *** ******* *** ***** ** software ********* ********** **** ***’* ******* literal ****** **** ******* ** ********* element *******?

(1)
RS
Robert Shih
Oct 09, 2021
Independent

* *** ******* *** ***** **** the ****** **** *** ****** ****** software ** ****** **** ********* *** review ** **** * *** **** songs *** **.

*******, ***** *** ***** ***** *** situations **** **** **** ********* **** varying ********. ** *** ***** ** Google **. ****** ** * ***** example, *** *** *** ***** **** the **** *** ******** ******. ************ speaking, * *** **** *** ** the ******** ** *** ********* ****.

******** *** *** ***: ********* ** the ****** - ********* - **** University - ******

*********, **** ** *** **** ** minimal, ** *** ***** ** *** taken ** ***** **** *** ** said *** ****. *** **** ***** stifles ****** ** **** ***** ** there *** ********* ***** *** **** to ******** *** ***** *** ** reason ***** **** ** ***** ****** accusations ** ****** ****

(1)
U
Undisclosed #2
Oct 09, 2021
IPVMU Certified

*********, **** ** *** **** ** minimal, ** *** ***** ** *** taken ** ***** **** *** ** said *** ****.

*** *** **** *** **** ****** aware ** **** ********** *** ***********? As ** *******, ****** * ********* a ** ****** **** *’* ***** to *********** ********** ** * ****** ****?

* *** ***** ** ********.

(1)
RS
Robert Shih
Oct 10, 2021
Independent

** ****** ****** ** **** ****** trolls ***** *** **** **** ** all **** *********. ***** **** ****, I *** **** ***** ** *****.

* **** *** ******** ** *** current ***** ********* **** **** *** AV1 ***** ** * ********* ******** to *.***/****, ***** *** ***** ** be **** ****** *** *******-****. *******, it *** **** ********* **** ** such ****** ******. **'* *** ******* microcosm ** *** ** ***'* **** nice ******.

(1)
UM
Undisclosed Manufacturer #1
Oct 07, 2021

*** ** ********* **** *** *** average **** *** **** ** *** the *************** ****** *********/*****?

** ***** *** **** **** ****/**** has ** **** *** *** **** comparable?

UE
Undisclosed End User #4
Oct 08, 2021

***** ** *** ********* ************* ********** ************* *** ***** ** *** for "*****" ****** **********. *** ***** 9/22, ******* *** **** **** ** reproduce **** ** */**.

U
Undisclosed #2
Oct 07, 2021
IPVMU Certified

***** *** ***** ** ***** *************** may ***** *** ****** ** ** compromised ** ********, ********** *** ** these *************** ******** ************* **********, *.*., a **** **** ** ****** **** an **** ****** ** ****.

*** ** ***** *** ****** **** CAN’T ** *********** ** ******* ** logged ** ** ****?

(2)
(1)
(1)
bm
bashis mcw
Oct 07, 2021

**, * ***** **** ***, **'* like ****** ****;

****@***:/****/***# ** - ****

****@***:~#

***** ** ** *************** *******, ** I *** *** *** *** ******** question.

*****, **** ***** *** ***************, *** useful, * ***'* ****.

(1)
U
Undisclosed #2
Oct 08, 2021
IPVMU Certified

*****, **** ***** *** ***************, *** useful, * ***'* ****.

*** ****** ****** - ** *** first **** ** ** ****** ****:

*******, *** **** ******** ******** ****** to ****** (** ******** ** *** official ******* *************) **** ** **** than “****” ********** **** “*****” ****** of ***** *** ****** ** *** libcurl *********** ******.

*** ***** ** ** *** *****. In ** **********, **** ******* *** have * ****** ******** **** *** mean ** *** ** *********.

***** *** **** ******* ********* ******* uid=0 *** ******* * ***?

bm
bashis mcw
Oct 08, 2021

**** (***=*) ** ****, ** *******/*** actually ******.

******, * ******* ** *** **** based ******** (*** *** ***** ***** buffer ********), *** ********** ** ************.

[****]

*** ***** ** ** *** *****. In ** **********, **** ******* *** have * ****** ******** **** *** mean ** *** ** *********.

****, **** **** *** *** **** heap ** ***** ***** ********, *** in ******* *** ***'* ** ****.

(1)
UI
Undisclosed Integrator #3
Oct 08, 2021

* ************* ** * ************* **** if *** ***'* *********** ********* **. Just ******* ** ***'* * * or * **** ***** *****'* **** it's *** ***** ****** *********. ********* it ***** * ***** ** *************** being **** ** ********** **** ** form * ********* *******. ***** ** Axis *** ***** ** ********! * just **** * ******* ***** ******* which * **** *** **** **** security ** *********...

(5)
bm
bashis mcw
Oct 08, 2021

**** ** **** ****, ******** *************** is *** **** ***** **** *** also **** *********.

(1)
U
Undisclosed #2
Oct 08, 2021
IPVMU Certified

* ************* ** * ************* **** if *** ***'* *********** ********* **. Just ******* ** ***'* * * or * **** ***** *****'* **** it's *** ***** ****** *********.

* *****, **’* ** ***** *** Axis ** **** *** ***** **. If **** *****’* ***** ** **, they ***** *** *** **** ** some ***-***** ******** ** ***** ** could ** ********* ** * ******* user. *** **** ** **** **** you ***** **** **** ****** *** an ****** *******.

**** ** * *** *** **** the ****** ***** *****, ***** **’* just * ****-**** ****-***-***.

* ***** *** *’* ********* ** is *** ****** *** *******, * feel ** ******** *** ***** ********* vulnerabilities *** *****.

Avatar
Ethan Ace
Oct 08, 2021

* ***** *** *’* ********* ** is *** ****** *** *******, * feel ** ******** *** ***** ********* vulnerabilities *** *****.

** ** ****, ***** *** *** levels ***** ****** (**** *** ********), so **'* *** **** *** ** the *****, *** * *.* ** just ***** *** **** *****.

*** ********** **** ******* ***** **** an **** ****** **** ** * browser, ****** ** ** ****, *** then ***** * ******** **** ** exploit **** **** ******* *** ******* is ****** ***, *** **'* *** 0, *** *** ********* ****** ** very ****, ** ******* ** ****** enough.

*** * ** *****, **'* *** a *.*.

U
Undisclosed #2
Oct 08, 2021
IPVMU Certified

…******* ***** **** ** **** ****** open ** * *******, ****** ** as ****, *** **** ***** * phishing **** ** ******* **** **** outside *** ******* ** ****** ***

****** ***** **** **** ***** ******** in **** ****. *** ******** **** could **** ****** *** **** ******** and ****** ***. ** *** ***** config ***** * ********.