Dahua New Critical Vulnerability 2019

Published Sep 23, 2019 12:51 PM

Dahua has quietly admitted 5 new vulnerabilities including 1 critical vulnerability with a 9.8 / 10.0 CVSS score and 2 high vulnerabilities (scored 7.0 - 9.0), found by researchers from the University of Applied Sciences Offenburg who are setting up a startup, IoT Security Systems.

IPVM Image

Inside this note, we examine the severity of these vulnerabilities, Dahua's response and impact on dealers and OEMs of Dahua.

These vulnerabilities are in addition and separate from the Dahua wiretapping vulnerability disclosed last month.

Vulnerabilities **********

***** *** ************* *** ***************:

IPVM Image

*** **** ****** (***-****-****) **** "** ******** *** ***** a ****** ******** ** ************ ********* packets". ** ********** *** *********** ******** ** ******** ********* **** **** ************* "****** an ******** ** ******* ********* **** on *** ******". **** ** *** it ******** **** * ******** (*.* out ** **.*) ***** ***** ******* can **** **** *** ******, ****** to ****** *** ***** *** ******** directly ** ** *** ** ** attack ***** ******* *******.

***** *** ******** **** **** ******* access ** *** *******, ** ******** **** ******** ** **********, ***** *** * ***** ****** of ***** ******* ********* ** *** public ********.

Collection ** **********

************** **** ******** * ********** ** the ********** **** *******.

Models ********

*****'* ******************** * **** ** ***** ******, while ** ***** * ****, ** estimate ** ** ****** ****** ** total ******:

IPVM Image

***** ****** *** ***** ********** ***** to ***-**** *******. *******, *** ******** up ***** ****** **** ** ********.

***** ********* ***** ********* ***** ***** being *** ****** '***** ** ** affected' *** ** ***** ******* **** would **** *** ** **** ** this ***** ***** *** *********** ******** this ** ***** * ****** ***, in ***.

Dahua ******** - ** *********, *** *******

***** ** ******* ****** * *********** ********* **, ****. ** ***** nothing ***** **** ***** ******** ****************, *** ********* *** **** ***** backdoor, ****** **** ********* **** **, partial ********* *****:

IPVM Image

** ******* *** ** ***** ** the ********* ****, **** ****** ********* *** *** ** ************* ***** ** ** *****, ********* 23rd *** ** ******. ***** ***** only **** *****'* *********** *************:

IPVM Image

**** ***** *** ******* *** ******** remains *******. ** **** *** *******'* ****.

****

*********, ***** **** *** ******** ******* the *********** ********** ***** *************** ** OEMed ***** *******, **** **** ********** to ****:

*** *************** **** ********** ********** ** a *****-******* ****** **** ***** *** the ******* *** *** *** ******** the *** ******** **** *****

** ****** ***** ***** *** ********* ****** the *********** ************* ******, ** ** *** ***** **** or ** *** ******* ***** **** will ** **.

**** ** *** ******* ******* ** the ******* ** ****** **** ****, even **** ** **** *** ******* of ****** **** *****.

Issues ******** *** *****

***** *** **** ******* ********* ***** claiming ** ******* ***** *************, ********* an*********** ***** ***** '************* ********' **** * ******* ***** **** compares ***** ** * ****** ******* female:

** **** ******* **** *****, *** Dahua ******* ************ **** **** ***** problems '**** * ***** ***'. **** new ****** ** ***************, ********* ***** high *** ******** ******, **-****** ***** significant ******** ***** *****'* ************* ***************.

Comments (29)
U
Undisclosed #1
Sep 23, 2019

**** ***** ** ******-********. * **** it *****'* *** **** ************, *** it ***** *** *** ********** **** a *** **** ** *****'* ***** security ******** ********** *** ****** ******* produce ***** ******** ** ***** ***.

(2)
(13)
UI
Undisclosed Integrator #5
Sep 25, 2019

**** *** **** ********* ****

U
Undisclosed #6
Sep 25, 2019

*** *** ** ****** **** *******!

U
Undisclosed #2
Sep 23, 2019

* *** ****** *** **** ********** into *** ******* ****-****** *****...

”*** ****, * **** **** *******.”

”***, ****, ** **** ******** ********, big ***?”

”****, ****... *’* ***** ** ** a **** ****, * **** *** to ***** ** *******.”

**** ***** *** ****, ** **** out **’* *** ***********, *********.

***’* **** *** *** **** **** he’s ******* * ********!

(1)
(1)
(3)
(23)
UI
Undisclosed Integrator #3
Sep 23, 2019

****, **** * *** ****** *** timeline ** **** ***... :)

***** *** **** ****** *********** *** at ***** * ****** ** ***** on ********** ***** ***************. * ******* that **** ** *** ******** ******* have **** ******** ** *** **** a **** ***** *** **'* ** update *** ******** *******.

*'* *** ******** ** *** ***** with ******* ** *************, *** **** do (*********, *******) *** ****** **** are ******.

** ** ** *****, *** ****** needs ** ** ***** ********** **** the ********... ***-******, **********, *** ********* and *** ********** ***** ****** *** be ********** ****. ****** ****** ******** and ****** *** ******** ******** ** course!

****** *** * ********** *** *************, its *** ************ **** ** ******** and * (** *****) **** ****** deployment ********* ****.

** *** **** ** ***********, ********* has ******* ****** ** ***'* ** Windows ****** ** *** **** ***** alone. ***** *** *** **** ** CVE's ******** *** *****, *** *** Huawei ********. ***** *** ***** ********* like ** ****-***** ********* ** ***** products

*. ***** *****, ***** *****

*. ****** *** ****** *********

*. ****** ******* ********

(2)
(6)
(1)
JH
John Honovich
Sep 23, 2019
IPVM

********* *** ******* ****** ** ***'* in ******* ****** ** *** **** month *****. ***** *** *** **** 70 ***'* ******** *** *****, *** and ****** ********.

********* ************* ***** ** *** ***** counts ** *****. *** ***** *** made * ******** ***** ***********, *** ******* ***** ***:

** ** *****, *** ****** ***** with **** *********** ** **** ******* software ****** *** ****** *** *** equal. ********* ******** **** ****** ** magnitude **** ******** **** ***** *** is ***** *** **** ******** **** Dahua.

** *** ********* ********** ******** ***** whether ***** *************** ****** ** *** should ** *********** (*.*., ********** ** manufacturer, ***.) *** ***** ********** *** count *** '*******' ** ******* ************* is **********.

(4)
(1)
(1)
UI
Undisclosed Integrator #3
Sep 25, 2019

****,

*** '****** ** ***' *** *** validating ** ******* ** ******* **** so * ********* *** ** *** data ****** *******... (***** **'* ***** me **** **** ** ******* **** reply)

** *** ** ***** - ****(***** ** *** ***** *** ********* vulnerabilities)

*** **** ******* ** ******** ********** here:*****://***.*****.***/****/*********/********.***

** ********* ** "********* *** ******* around ** ***'* ** ******* ****** in *** **** ***** *****. ***** are *** **** ** ***'* ******** for *****, *** *** ****** ********." is **** *******.

*** *** **** * *****, **** are *** ******* ** ************:

*********: **** = *, **** = 2, **** = *

*****: **** = *, **** = 0, **** = **

******: **** =**, **** = **, 2017 = ***

***** **** = **, **** = 55, **** = ***

*********: **** = ***, **** = 479, **** = ***

*+*+* ** % ** ********* = 2019 = **.*%, **** = **.*%, 2017 = **%

** ********* ** ********* *** ** put ** ** ******* *******. (** would ** *********** ** *** ** Microsoft ***** ******** ****** ******** *** software ** **** ***** ** * better ***!)

** ** *****. *** *************** *** important *** **** ** ** *********. In *** ******** ********, ** ***** a **** ****** ******** ** ****** secure ******** - * *** *** mean ** **** *** ********** ** the ********!!!

********** ** ****** ** *******, ***** to ****** ** ********** ** *** body ** ************, **, ** *********** installers/designers/maintainers **** ***** * ****** ***** on ********* ********* ** **** * way **** *** ****** ************* ** mitigated ** *** *********** ** ******* for **.

* ***** ******* ** **** *** the ****** *********** ***** ******* **** outlets ******* **** *** ******** ** the ***** **** *** ******* ********** can *** ********** ** *** *** cameras. **** ****** ** **** ** the **** ******* ******* **** *** all ********* *** *** ** *** CCTV ******** *** ********** ******** **** each ***** *** ** *** ** anywhere **** ************** ******* ********* (*** tube ******* **** *** **** *** railway ***** *** **, ** ** they **** ************ ******* *** *****, they **** ** * *****)

** ***** *****, **** ** ***** was * ************* **** ******** *** CCTV ******'* *********, ** ***** *** not **** ****** ******* ****** *** could ** **** **** ******** ** (forgive ** *** ** *** **** overly **** ****** ** ********** ***** journalism) '**** *****'

(1)
bm
bashis mcw
Sep 25, 2019

**** * **** ** **** *** comments...

*** *********** *** ***self ******* *** ********** ***** ********* will do their CVE's, no matter if the vulnerability has been found in-house or reported from externally.

**** ************ ** *** **** *** CVE's ** ***, ********** ** ** notifications ** ******** ***** *** *********. That ***** ******* **** *******.

(1)
(2)
JH
John Honovich
Sep 25, 2019
IPVM

**** ************ ** *** **** *** CVE's ** ***, ********** ** ** notifications ** ******** ***** *** *********

******, **** *****. *'* *** **** when * ******* ****** ****** *** cybersecurity *********** ** *** *****, **** have * ******* ************ ** **** CVEs.

(2)
JH
John Honovich
Sep 25, 2019
IPVM

** ********* ** "********* *** ******* around ** ***'* ** ******* ****** in *** **** ***** *****. ***** are *** **** ** ***'* ******** for *****, *** *** ****** ********." is **** *******.

*** *** ******?

*** **** ***:

******: **** =**, **** = **, 2017 = ***

** ** ** **** *** *********** Huawei *** *** ** *** **** 3 *****, *** *** *** ******** you *** '**** *******' ** *** "***** *** *** **** ** ***'* combined *** *****, *** *** ****** combined"??

*****, ** ** *****, ******* ** evaluating ******* ***** ** *** ***** is ********** *** **** ** **** own *****, *** *** *****. * just **** *** ** ** **** sloppy *** ** ****** ****-********.

** ***** ** *********** ** *** if ********* ***** ******** ****** ******** and ******** ** **** ***** ** a ****** ***!

** ***** ** *** ****** *** conclude ********* ** ***** * '*****' or '******' *** **** ***** ***** on *** ******. ********* ******** **** or ***** *** ****** ** **** Dahua *** ** ***** *** ** 100x, ***. *** ****** ** ******** of *****.

***** ********* ** ***** ** ******** development **** ***** *** ****** **** on *** ****** ** ******* ***** you ***'* ****** ******* *** ****** across *********.

(2)
(1)
UI
Undisclosed Integrator #3
Sep 25, 2019

****** * ***** ****** **** ******** post... ** ******** **** ***** ** 2019 ****. * ******** *** **** three ***** ** **** *******.

JH
John Honovich
Sep 25, 2019
IPVM

** ******** **** ***** ** **** only

**,**** ******** ******* ***:

** *** **** ** ***********, ********* has ******* ****** ** ***'* ** Windows ****** ** *** **** ***** alone. ***** *** *** **** ** CVE's ******** *** *****, *** *** Huawei ********.

*****, *** ** *** **** ******** on *** ******? ** *** ****** think *** *** ************ *** ************ compare ***** ** ********* ***** ** CVE ******? **** *** ** *** points ***** *** ********* ***** ****** different ** ***** ** *********** *** scrutiny **** *** ***** ** ***?

*** *** * *** *********** ********* the ****** ** ****** ***** ** an ******** ******* ** * ***.

(1)
U
Undisclosed #7
Sep 25, 2019

"***** ********* ** ***** ** ******** development **** ***** *** ****** **** on *** ****** ** ******* ***** you ***'*fairly ******* *** ****** ****** *********"

*** **** ***** ****** ** *** for **** **********?

JH
John Honovich
Sep 25, 2019
IPVM

* ***'* **** **** ****** ****** would ** **** / ********. ****** with *****, **** **** ** *****.

(1)
U
Undisclosed #7
Sep 26, 2019

***** *** *** ****** ** **** metric?

*** **** ***** **** **** ******* of *** *******

*** ***** **** ******* ** *** "cameras" ************* *******

JH
John Honovich
Sep 26, 2019
IPVM

********* **** ********** $*** *******.

*** ****** ****** ***** ************ ****** was ****** ** **** **** $** billion.

**'* * *** **** ** ******* a ******* ***** ******* ** * to ** *** **** ** ** entire ********.

(1)
U
Undisclosed #7
Sep 26, 2019

*** ***** ***** *******

****** *** **** ***** *** **** lost ******* ** **** "******" **

JH
John Honovich
Sep 26, 2019
IPVM

****** *** **** ***** *** **** lost ******* ** **** "******" **

** ***** ** ****** ** ************* than *********?

** *** '*** ***** ***** *******', losses **** ** ** ******** ** revenue ** ********** ******** ****** *** net **** ** ****.

(1)
U
Undisclosed #7
Sep 26, 2019

*** *** *** ******* ** ******* of *** **** ***** **** **** because ** *****

************* *******!

JH
John Honovich
Sep 26, 2019
IPVM

*****'* ********* *** ***** ******* ** the ******** ** **** ***** * lot ** ****** **** ****** **** on ***** -***** ********* **** ******

U
Undisclosed #4
Sep 25, 2019
IPVMU Certified

** ********* ** "********* *** ******* around ** ***'* ** ******* ****** in *** **** ***** *****. ***** are *** **** ** ***'* ******** for *****, *** *** ****** ********." is **** *******.

****** **** ********* ** ********* * software *******, *** *** ****** *** primarily ******** *********.

*** ******* ** ********* ******** ** immense:everything **** ******** ********* *******, ******** browsers, ** ****** ************, ** ***, to ******, ** ********* *****, ** remote ****** *** ** **...

***** ******** ** *****, ******** ********, tools, **, ?

*** **** **** ***** ** **** does ********* ******* **** *+*+* ?

****** **** ** ** **** ********

*+*+* ** % ** ********* = 2019 = **.*%, **** = **.*%, 2017 = **%

(2)
Avatar
Brian Hampton
Sep 25, 2019
IPVMU Certified

** ** *** **** ****** *** Dahua, **** ** *** ***** **** I've ***** ** ***** ***************. ***** has * ******* ** **** ************* and *'* ******* ***** ** **. This ******** **** *** ****** ** ignore **** *************** **** ******** ** "it's ** *** ****" ** ***. Their ********* **** ********** **** ** their ********. ***** ** **** **** a ***** *******, *** **** ***'* figure *** *** ******** ****.

(1)
(2)
(2)
JH
John Honovich
Sep 25, 2019
IPVM

*****, ** **** ***** ***** * few ***** *** * **** **** are ********. ** ** ******** **** Dahua *** ****** *** *** ******** though ** ** **** ** **** given *****'* ******* ******** *** ***** naming ***********. ****** ***, ***** *** should ******* ****** ***** ********. ** we *** *** ********, ** **** update ****.

(1)
U
Undisclosed #4
Sep 23, 2019
IPVMU Certified

**** *** ** *** ** *** league, ***’* * ***** *! *** needs * **** *********** *******:

****** **** ******* ** ** *****, as ** ** ********** * ******, and *** **** ***** ** **** out ********* ** * ****...

*** ***, ******* *** ******* *******, is ***** ***** ********** :)

(1)
bm
bashis mcw
Sep 23, 2019

*********** *****, *******,

[*] *****'* **** ** ** "***-*********-*, Build: ****-**-** **:**:**, *******: *.***.*******.**.*" ** it *** ****** *** *** *****.

[*] ***** *** ** ** ******* on ***** ****** ******.

* **** *** **** [*] & [5] ** *** ***********, ** **** reporting ****** ********... (**, **** **** my ***, *** * ***** ***** is ******* ********** */ ********** ******* and **** ***** **)

********, * ******* ***** **** *** Debug *****/********* ****** ** ********!

[*], [*] *** [*] ** ****** know, ******* ***.

[*] ** ********, ** * ****'* spend **** ** **, *** ***** interesting.

(3)
bm
bashis mcw
Dec 08, 2019

***** **** *** '*****-**' *** **** '******-****', ** *** * **** *********?

(1)
UI
Undisclosed Integrator #8
Dec 09, 2019

****** **** *** ****** ****** ***'* say ******** ***** *** ******** ******* on ***** ******** ********. ****** ******** doesn't **** * ******** *******.

*** ****** ************ **** ****** **** September.

*** **** ***** * *** **** using ****, *** ***** ***-*** ** response ** ****** ***** ** ***** TLS ***********. ** **** ****** ***** hosting *******, *'* *** **** *** the ****** ***** ******* **** ***, unless *** ******* ******* ** ****** to ******** ****** ** *** ********** in **** *** ******* ** ********.

**'* **** ******** **** *** * speculative *******, **** ***** ** *** a *** ***** ** ******, *** then ******* ** ******'* ****.

TV
Thomas Vogt
Jan 27, 2020

**'* **** ******** **** *** * speculative *******, **** ***** ** *** a *** ***** ** ******, *** then ******* ** ******'* ****.

*** *** ***** ;) - ** was *** ***** **** ** ***** our *** ********.

(1)
JH
John Honovich
Dec 09, 2019
IPVM

* ******* *** ******* ** *** group ** *******. *** ***** ** that ****** **** *** *** ******, fyi. ** ** **** **** *******, I'll ****** ***********.