This is an IPVM report available to you via this special link only until Jun 23, 2024 04:00 AM

Dahua New Critical Vulnerability 2019

Published Sep 23, 2019 12:51 PM

Dahua has quietly admitted 5 new vulnerabilities including 1 critical vulnerability with a 9.8 / 10.0 CVSS score and 2 high vulnerabilities (scored 7.0 - 9.0), found by researchers from the University of Applied Sciences Offenburg who are setting up a startup, IoT Security Systems.

IPVM Image

Inside this note, we examine the severity of these vulnerabilities, Dahua's response and impact on dealers and OEMs of Dahua.

These vulnerabilities are in addition and separate from the Dahua wiretapping vulnerability disclosed last month.

Vulnerabilities Overviewed

Dahua has acknowledged 5 new vulnerabilities:

IPVM Image

The most severe (CVE-2019-9677) lets "an attacker can cause a buffer overflow by constructing malicious packets". In a statement the researchers provided to IPVM they confirmed that this vulnerability "allows an attacker to execute malicious code on the camera". This is why it received such a critical (9.8 out of 10.0) score since attacks can take over the camera, either to access its feeds and contents directly or to use it to attack other network devices.

While the attacker will need network access to the devices, as the Dahua mass hackings in 2017 showed, there are a large number of Dahua devices available on the public Internet.

Collection of Advisories

The researchers have released a collection of the advisories with details.

Models Impacted

Dahua's announcement included a list of known models, while it shows 8 rows, we estimate it to impact dozens of total models:

IPVM Image

These models are older generation lower to mid-tier cameras. However, all firmware up until August 2019 is impacted.

Dahua qualifies their statement about these being the models 'known to be affected' but we would presume they would know all of them at this point since the researchers reported this to Dahua 4 months ago, in May.

Dahua Response - HQ Statement, USA Nothing

Dahua HQ quietly issued a statement on September 14, 2018. We heard nothing about this until security researcher Bashis, who uncovered the 2017 Dahua backdoor, shared this statement with us, partial screencap below:

IPVM Image

We reached out to Dahua on the September 18th, also noting that Dahua USA had no disclosure and still as of today, September 23rd has no notice. Below shows only last month's wiretapping vulnerability:

IPVM Image

What Dahua USA cameras are impacted remains unclear. As does all of Dahua's OEMs.

OEMs

Certainly, Dahua OEMs are impacted because the researchers originally found vulnerabilities in OEMed Dahua cameras, with them explaining to IPVM:

The vulnerabilities were originally identified on a white-labeled device from Dahua and the company has not yet released the new firmware from Dahua

As the one month delay for Honeywell fixing the wiretapping vulnerability showed, it is not clear when or if the various Dahua OEMs will do so.

This is yet another example of the dangers of buying from OEMs, even more so than the dangers of buying from Dahua.

Issues Continue For Dahua

Dahua has made various marketing moves claiming to improve their cybersecurity, including an infographic about their 'Cybersecurity Baseline' with a YouTube video that compares Dahua to a petite fitness female:

In that January 2019 video, the Dahua actress dismissively says that their problems 'were a while ago'. This new series of vulnerabilities, including their high and critical nature, re-raises those significant concerns about Dahua's cybersecurity vulnerabilities.

Comments (29)
U
Undisclosed #1
Sep 23, 2019

**** ***** ** ******-********. * **** it *****'* *** **** ************, *** it ***** *** *** ********** **** a *** **** ** *****'* ***** security ******** ********** *** ****** ******* produce ***** ******** ** ***** ***.

(2)
(13)
UI
Undisclosed Integrator #5
Sep 25, 2019

**** *** **** ********* ****

U
Undisclosed #6
Sep 25, 2019

*** *** ** ****** **** *******!

U
Undisclosed #2
Sep 23, 2019

* *** ****** *** **** ********** into *** ******* ****-****** *****...

”*** ****, * **** **** *******.”

”***, ****, ** **** ******** ********, big ***?”

”****, ****... *’* ***** ** ** a **** ****, * **** *** to ***** ** *******.”

**** ***** *** ****, ** **** out **’* *** ***********, *********.

***’* **** *** *** **** **** he’s ******* * ********!

(1)
(1)
(3)
(23)
UI
Undisclosed Integrator #3
Sep 23, 2019

****, **** * *** ****** *** timeline ** **** ***... :)

***** *** **** ****** *********** *** at ***** * ****** ** ***** on ********** ***** ***************. * ******* that **** ** *** ******** ******* have **** ******** ** *** **** a **** ***** *** **'* ** update *** ******** *******.

*'* *** ******** ** *** ***** with ******* ** *************, *** **** do (*********, *******) *** ****** **** are ******.

** ** ** *****, *** ****** needs ** ** ***** ********** **** the ********... ***-******, **********, *** ********* and *** ********** ***** ****** *** be ********** ****. ****** ****** ******** and ****** *** ******** ******** ** course!

****** *** * ********** *** *************, its *** ************ **** ** ******** and * (** *****) **** ****** deployment ********* ****.

** *** **** ** ***********, ********* has ******* ****** ** ***'* ** Windows ****** ** *** **** ***** alone. ***** *** *** **** ** CVE's ******** *** *****, *** *** Huawei ********. ***** *** ***** ********* like ** ****-***** ********* ** ***** products

*. ***** *****, ***** *****

*. ****** *** ****** *********

*. ****** ******* ********

(2)
(6)
(1)
JH
John Honovich
Sep 23, 2019
IPVM

********* *** ******* ****** ** ***'* in ******* ****** ** *** **** month *****. ***** *** *** **** 70 ***'* ******** *** *****, *** and ****** ********.

********* ************* ***** ** *** ***** counts ** *****. *** ***** *** made * ******** ***** ***********, *** ******* ***** ***:

** ** *****, *** ****** ***** with **** *********** ** **** ******* software ****** *** ****** *** *** equal. ********* ******** **** ****** ** magnitude **** ******** **** ***** *** is ***** *** **** ******** **** Dahua.

** *** ********* ********** ******** ***** whether ***** *************** ****** ** *** should ** *********** (*.*., ********** ** manufacturer, ***.) *** ***** ********** *** count *** '*******' ** ******* ************* is **********.

(4)
(1)
(1)
UI
Undisclosed Integrator #3
Sep 25, 2019

****,

*** '****** ** ***' *** *** validating ** ******* ** ******* **** so * ********* *** ** *** data ****** *******... (***** **'* ***** me **** **** ** ******* **** reply)

** *** ** ***** - ****(***** ** *** ***** *** ********* vulnerabilities)

*** **** ******* ** ******** ********** here:*****://***.*****.***/****/*********/********.***

** ********* ** "********* *** ******* around ** ***'* ** ******* ****** in *** **** ***** *****. ***** are *** **** ** ***'* ******** for *****, *** *** ****** ********." is **** *******.

*** *** **** * *****, **** are *** ******* ** ************:

*********: **** = *, **** = 2, **** = *

*****: **** = *, **** = 0, **** = **

******: **** =**, **** = **, 2017 = ***

***** **** = **, **** = 55, **** = ***

*********: **** = ***, **** = 479, **** = ***

*+*+* ** % ** ********* = 2019 = **.*%, **** = **.*%, 2017 = **%

** ********* ** ********* *** ** put ** ** ******* *******. (** would ** *********** ** *** ** Microsoft ***** ******** ****** ******** *** software ** **** ***** ** * better ***!)

** ** *****. *** *************** *** important *** **** ** ** *********. In *** ******** ********, ** ***** a **** ****** ******** ** ****** secure ******** - * *** *** mean ** **** *** ********** ** the ********!!!

********** ** ****** ** *******, ***** to ****** ** ********** ** *** body ** ************, **, ** *********** installers/designers/maintainers **** ***** * ****** ***** on ********* ********* ** **** * way **** *** ****** ************* ** mitigated ** *** *********** ** ******* for **.

* ***** ******* ** **** *** the ****** *********** ***** ******* **** outlets ******* **** *** ******** ** the ***** **** *** ******* ********** can *** ********** ** *** *** cameras. **** ****** ** **** ** the **** ******* ******* **** *** all ********* *** *** ** *** CCTV ******** *** ********** ******** **** each ***** *** ** *** ** anywhere **** ************** ******* ********* (*** tube ******* **** *** **** *** railway ***** *** **, ** ** they **** ************ ******* *** *****, they **** ** * *****)

** ***** *****, **** ** ***** was * ************* **** ******** *** CCTV ******'* *********, ** ***** *** not **** ****** ******* ****** *** could ** **** **** ******** ** (forgive ** *** ** *** **** overly **** ****** ** ********** ***** journalism) '**** *****'

(1)
bm
bashis mcw
Sep 25, 2019

**** * **** ** **** *** comments...

*** *********** *** ***self ******* *** ********** ***** ********* will do their CVE's, no matter if the vulnerability has been found in-house or reported from externally.

**** ************ ** *** **** *** CVE's ** ***, ********** ** ** notifications ** ******** ***** *** *********. That ***** ******* **** *******.

(1)
(2)
JH
John Honovich
Sep 25, 2019
IPVM

**** ************ ** *** **** *** CVE's ** ***, ********** ** ** notifications ** ******** ***** *** *********

******, **** *****. *'* *** **** when * ******* ****** ****** *** cybersecurity *********** ** *** *****, **** have * ******* ************ ** **** CVEs.

(2)
JH
John Honovich
Sep 25, 2019
IPVM

** ********* ** "********* *** ******* around ** ***'* ** ******* ****** in *** **** ***** *****. ***** are *** **** ** ***'* ******** for *****, *** *** ****** ********." is **** *******.

*** *** ******?

*** **** ***:

******: **** =**, **** = **, 2017 = ***

** ** ** **** *** *********** Huawei *** *** ** *** **** 3 *****, *** *** *** ******** you *** '**** *******' ** *** "***** *** *** **** ** ***'* combined *** *****, *** *** ****** combined"??

*****, ** ** *****, ******* ** evaluating ******* ***** ** *** ***** is ********** *** **** ** **** own *****, *** *** *****. * just **** *** ** ** **** sloppy *** ** ****** ****-********.

** ***** ** *********** ** *** if ********* ***** ******** ****** ******** and ******** ** **** ***** ** a ****** ***!

** ***** ** *** ****** *** conclude ********* ** ***** * '*****' or '******' *** **** ***** ***** on *** ******. ********* ******** **** or ***** *** ****** ** **** Dahua *** ** ***** *** ** 100x, ***. *** ****** ** ******** of *****.

***** ********* ** ***** ** ******** development **** ***** *** ****** **** on *** ****** ** ******* ***** you ***'* ****** ******* *** ****** across *********.

(2)
(1)
UI
Undisclosed Integrator #3
Sep 25, 2019

****** * ***** ****** **** ******** post... ** ******** **** ***** ** 2019 ****. * ******** *** **** three ***** ** **** *******.

JH
John Honovich
Sep 25, 2019
IPVM

** ******** **** ***** ** **** only

**,**** ******** ******* ***:

** *** **** ** ***********, ********* has ******* ****** ** ***'* ** Windows ****** ** *** **** ***** alone. ***** *** *** **** ** CVE's ******** *** *****, *** *** Huawei ********.

*****, *** ** *** **** ******** on *** ******? ** *** ****** think *** *** ************ *** ************ compare ***** ** ********* ***** ** CVE ******? **** *** ** *** points ***** *** ********* ***** ****** different ** ***** ** *********** *** scrutiny **** *** ***** ** ***?

*** *** * *** *********** ********* the ****** ** ****** ***** ** an ******** ******* ** * ***.

(1)
U
Undisclosed #7
Sep 25, 2019

"***** ********* ** ***** ** ******** development **** ***** *** ****** **** on *** ****** ** ******* ***** you ***'*fairly ******* *** ****** ****** *********"

*** **** ***** ****** ** *** for **** **********?

JH
John Honovich
Sep 25, 2019
IPVM

* ***'* **** **** ****** ****** would ** **** / ********. ****** with *****, **** **** ** *****.

(1)
U
Undisclosed #7
Sep 26, 2019

***** *** *** ****** ** **** metric?

*** **** ***** **** **** ******* of *** *******

*** ***** **** ******* ** *** "cameras" ************* *******

JH
John Honovich
Sep 26, 2019
IPVM

********* **** ********** $*** *******.

*** ****** ****** ***** ************ ****** was ****** ** **** **** $** billion.

**'* * *** **** ** ******* a ******* ***** ******* ** * to ** *** **** ** ** entire ********.

(1)
U
Undisclosed #7
Sep 26, 2019

*** ***** ***** *******

****** *** **** ***** *** **** lost ******* ** **** "******" **

JH
John Honovich
Sep 26, 2019
IPVM

****** *** **** ***** *** **** lost ******* ** **** "******" **

** ***** ** ****** ** ************* than *********?

** *** '*** ***** ***** *******', losses **** ** ** ******** ** revenue ** ********** ******** ****** *** net **** ** ****.

(1)
U
Undisclosed #7
Sep 26, 2019

*** *** *** ******* ** ******* of *** **** ***** **** **** because ** *****

************* *******!

JH
John Honovich
Sep 26, 2019
IPVM

*****'* ********* *** ***** ******* ** the ******** ** **** ***** * lot ** ****** **** ****** **** on ***** -***** ********* **** ******

U
Undisclosed #4
Sep 25, 2019
IPVMU Certified

** ********* ** "********* *** ******* around ** ***'* ** ******* ****** in *** **** ***** *****. ***** are *** **** ** ***'* ******** for *****, *** *** ****** ********." is **** *******.

****** **** ********* ** ********* * software *******, *** *** ****** *** primarily ******** *********.

*** ******* ** ********* ******** ** immense:everything **** ******** ********* *******, ******** browsers, ** ****** ************, ** ***, to ******, ** ********* *****, ** remote ****** *** ** **...

***** ******** ** *****, ******** ********, tools, **, ?

*** **** **** ***** ** **** does ********* ******* **** *+*+* ?

****** **** ** ** **** ********

*+*+* ** % ** ********* = 2019 = **.*%, **** = **.*%, 2017 = **%

(2)
Avatar
Brian Hampton
Sep 25, 2019
IPVMU Certified

** ** *** **** ****** *** Dahua, **** ** *** ***** **** I've ***** ** ***** ***************. ***** has * ******* ** **** ************* and *'* ******* ***** ** **. This ******** **** *** ****** ** ignore **** *************** **** ******** ** "it's ** *** ****" ** ***. Their ********* **** ********** **** ** their ********. ***** ** **** **** a ***** *******, *** **** ***'* figure *** *** ******** ****.

(1)
(2)
(2)
JH
John Honovich
Sep 25, 2019
IPVM

*****, ** **** ***** ***** * few ***** *** * **** **** are ********. ** ** ******** **** Dahua *** ****** *** *** ******** though ** ** **** ** **** given *****'* ******* ******** *** ***** naming ***********. ****** ***, ***** *** should ******* ****** ***** ********. ** we *** *** ********, ** **** update ****.

(1)
U
Undisclosed #4
Sep 23, 2019
IPVMU Certified

**** *** ** *** ** *** league, ***’* * ***** *! *** needs * **** *********** *******:

****** **** ******* ** ** *****, as ** ** ********** * ******, and *** **** ***** ** **** out ********* ** * ****...

*** ***, ******* *** ******* *******, is ***** ***** ********** :)

(1)
bm
bashis mcw
Sep 23, 2019

*********** *****, *******,

[*] *****'* **** ** ** "***-*********-*, Build: ****-**-** **:**:**, *******: *.***.*******.**.*" ** it *** ****** *** *** *****.

[*] ***** *** ** ** ******* on ***** ****** ******.

* **** *** **** [*] & [5] ** *** ***********, ** **** reporting ****** ********... (**, **** **** my ***, *** * ***** ***** is ******* ********** */ ********** ******* and **** ***** **)

********, * ******* ***** **** *** Debug *****/********* ****** ** ********!

[*], [*] *** [*] ** ****** know, ******* ***.

[*] ** ********, ** * ****'* spend **** ** **, *** ***** interesting.

(3)
bm
bashis mcw
Dec 08, 2019

***** **** *** '*****-**' *** **** '******-****', ** *** * **** *********?

(1)
UI
Undisclosed Integrator #8
Dec 09, 2019

****** **** *** ****** ****** ***'* say ******** ***** *** ******** ******* on ***** ******** ********. ****** ******** doesn't **** * ******** *******.

*** ****** ************ **** ****** **** September.

*** **** ***** * *** **** using ****, *** ***** ***-*** ** response ** ****** ***** ** ***** TLS ***********. ** **** ****** ***** hosting *******, *'* *** **** *** the ****** ***** ******* **** ***, unless *** ******* ******* ** ****** to ******** ****** ** *** ********** in **** *** ******* ** ********.

**'* **** ******** **** *** * speculative *******, **** ***** ** *** a *** ***** ** ******, *** then ******* ** ******'* ****.

TV
Thomas Vogt
Jan 27, 2020

**'* **** ******** **** *** * speculative *******, **** ***** ** *** a *** ***** ** ******, *** then ******* ** ******'* ****.

*** *** ***** ;) - ** was *** ***** **** ** ***** our *** ********.

(1)
JH
John Honovich
Dec 09, 2019
IPVM

* ******* *** ******* ** *** group ** *******. *** ***** ** that ****** **** *** *** ******, fyi. ** ** **** **** *******, I'll ****** ***********.