Hikvision Happy With Bad Security Unless Hit With Bad Press

By: John Honovich, Published on Aug 28, 2017

Hikvision is happy to have bad cyber security unless they are hit with bad press, as we detail inside.

When you look at the pattern of their behavior, it is clear that anyone concerned about cyber security is taking significant risks with Hikvision. Hikvision's marketing claims to care but Hikvision's actions show otherwise.

#1 - Emailing Admin Passwords Plain Text

Hikvision has been emailing iVMS-4200 admin passwords in plain text. And they do not even attempt to verify who requests it, anyone unauthorized just presses a button on the client and Hikvision will immediately email the admin password in plain text, e.g. how they responded to one of our requests:

Today, Hikvision finally did something.

Why? Because IPVM published Hikvision VMS Password Recovery Vulnerability.

Hikvision emailed its dealers a [Special Bulletin] Security Structure Update to iVMS-4200. That 'structure update', which they did not even explain, was to stop allowing people to request admin passwords emailed in plain text.

And this is, unfortunately, commonplace with Hikvision.

#2 - Cracked Security Codes

Get Notified of Video Surveillance Breaking News
Get Notified of Video Surveillance Breaking News

Hikvision has known for more than a year that its 'security codes' to reset its IP cameras and recorders were cracked and available as unauthorized online 'tools'. Many of their recorders still had no firmware upgrade fix available for this crack.

On August 8, 2017, IPVM published Hikvision Security Code Cracked.

Hikvision responded on August 10th with a [Hikvision Special Bulletin] Password Reset Update. The convoluted post misled their dealers, dismissing "so-called Hikvision 'security code' being 'cracked'". But that is what Hikvision called them - 'security codes' as shown from their own documentation:

And Hikvision did not have enough respect for their dealers to let them know that working generators for these security codes are still available online.

Worse, Hikvision is still allowing these unauthenticated resets with a new generator that they hope will not get cracked.

#3 - Hikvision Backdoor

On March 5th, 2017, a researcher announced a Hikvision camera backdoor (who later DHS gave credit to in Hikvision's worst 10.0 vulnerability advisory).

On March 10th, we emailed Hikvision telling Hikvision we planned to release an article on Monday, March 13th. And on Sunday, March 12, Hikvision again issued a [Hikvision Special Bulletin] Update on Privilege-Escalating Vulnerability. Again, Hikvision obscured the risk with the vague statement "obtain an unauthorized escalated additional user privilege". It was only until the DHS advisory was released that the public learned the true severity of the vulnerability.

#4 - Hikvision Defaulted Devices Mass Hacked

On March 2, 2017, IPVM published Hikvision Defaulted Devices Getting Hacked after weeks of ongoing reports from Hikvision dealers saying that their systems had been hacked. Hikvision knew well that this was happening but they said nothing to their dealers.

Until IPVM published, and then Hikvision immediately issued another [Hikvision Special Bulletin] Defense Against Scripted Application.

Public 'Proclamations'

Hikvision's poor practices occur despite their claims that Cisco 'recognized' their cybersecurity or that they hired Rapid7 to do vulnerability assessments. It is hard to imagine that Cisco or Rapid7 would approve of emailing admin passwords in plain text. It, evidently, is not so hard to imagine Hikvision accepting such practices.

Lessons Learned

These incidents show that Hikvision's actions fall far behind their marketing claims and even their communication to their 'partners' is focused on doing damage control and spinning bad press.

If you are serious about cyber security, you cannot seriously use Hikvision.

5 reports cite this report:

Hikvision Admits Backdoor 'PR Issue' on Oct 24, 2017
Hikvision is admitting a problem. The backdoor itself is evidently not the problem for them. The problem, according to Hikvision, is a public...
FLIR Thermal Camera Multiple Vulnerabilities, Patch Released on Oct 03, 2017
Multiple cyber security vulnerabilities exist in FLIR thermal cameras, which have not been fixed, despite being reported months ago. UPDATE- FLIR...
80+ OEMs Verified Vulnerable To Hikvision Backdoor on Sep 22, 2017
Over 80 Hikvision OEM partners, including ADI, Interlogix, LTS, and Northern Video, have been verified as having products vulnerable to the...
Hikvision Backdoor Exploit on Sep 03, 2017
Full disclosure to the Hikvision backdoor has been released, allowing easy exploit of vulnerable Hikvision IP cameras. As the researcher, Monte...
Fortune 500 Company Bars Dahua and Hikvision on Aug 30, 2017
A Fortune 500 company has barred Dahua and Hikvision cameras from a large RFP due to cyber security concerns, IPVM has confirmed with the...
Comments (30) : PRO Members only. Login. or Join.

Related Reports

Last Chance - Register Now - October 2019 IP Networking Course on Oct 10, 2019
Last Chance - Register Now - Fall 2019 IP Networking Course. The course starts next week. This is the only networking course designed...
Critical Vulnerability Across 18+ Network Switch Vendors: Cisco, Netgear, More on Aug 26, 2019
Cisco, Netgear and more than a dozen other brands, including small Asian ones, have been found to share the same critical vulnerability, discovered...
Dahua Wiretapping Vulnerability on Aug 02, 2019
IPVM has validated, with testing, and from Dahua, that many Dahua cameras have a wiretapping vulnerability. Even if the camera's audio has been...
"Stats Don't Lie" Says Deceptive IFSEC on Jul 30, 2019
While IFSEC has declared #statsdontlie and trumpeted seemingly skyrocketing visitor numbers, they are decieving about their show's problems. On...
Hikvision: In China, We Obey PRC Human Rights Law on May 28, 2019
Hikvision defended its activities in Xinjiang, where the PRC is accused of mass human rights abuses, by stating that human rights have a “varied...
LifeSafety Power NetLink Vulnerabilities And Problematic Response on May 20, 2019
'Power supplies' are not devices that many think about when considering vulnerabilities but as more and more devices go 'online', the risks for...
Inside Look Into Scam Market Research on May 17, 2019
Scam market research has exploded over the last few years becoming the most commonly cited 'statistics' for most industries, despite there clearly...
Verkada False Allegations Against Avigilon Exposed on May 08, 2019
Verkada has leveled false allegations against Avigilon, as part of their aggressive marketing tactics against the 'dinosaurs' in the 'ancient'...
Verkada Salesman: IPVM "Stuck In A The Stone Age" on Apr 25, 2019
Verkada is 'tackling dinosaurs' and battling those, like IPVM, who are 'stuck in a the stone age'. Verkada's recent sales recruiting promotion...
The Embarrassing Story of ISC West's Best New IP Camera on Apr 24, 2019
A sad but simple situation: Only 2 companies paid SIA the thousands of dollars required to compete for the best new 'cameras IP' The judges...

Most Recent Industry Reports

Honeywell 30 Series Cameras Tested Vs Dahua and Hikvision on Dec 11, 2019
Honeywell has infamously OEMed Dahua and Hikvision for years, but now they have introduced an NDAA-compliant line, the 30 Series, claiming "lower...
"Good Market, Bad Business Models" - Residential Security on Dec 11, 2019
Industry banker John Mack, at his company's annual event, took aim squarely at the problems in the residential security...
IP Camera Browser Support: Who's Broken / Who Works on Dec 10, 2019
For many years, IP cameras depended on ActiveX control, whose security flaws have been known for more than a decade. The good news is that this is...
Acquisitions - Winners and Losers on Dec 10, 2019
Most major manufacturers have been acquired over the last decade. But which have been good deals or not? In this report, we analyze the...
IP Camera Installability Shootout 2019 - Avigilon, Axis, Bosch, Dahua, Hanwha, Hikvision, Uniview, Vivotek on Dec 09, 2019
What are the best and worst cameras to install? Which manufacturers make it the hardest or easiest to install their cameras? We tested 35 total...
Viisights Raises $10 Million, Behavior Analytics Company Profile on Dec 09, 2019
Viisights, an Israeli AI analytics startup marketing "Behavioral Understanding Systems", announced $10 million Series A funding. We spoke to...
Disruptor Wyze Releases Undisruptive Smartlock on Dec 06, 2019
While Wyze has disrupted the consumer IP camera market with ~$20 cameras, its entrance into smart locks is entirely undisruptive. We have...
Bosch Budget 3000i Cameras Tested on Dec 05, 2019
Bosch has long had a hole in its lineup for, as it describes, "competitively-priced cameras". Now, Bosch has released its 3000i series cameras...
Anixter Resisting Takeover From Competitor on Dec 05, 2019
Mega distributor Anixter is going to be acquired but by whom? Initially, Anixter planned to go private, being bought by a private equity firm....
Security Sales Course 2020 - Last Chance Save $50 on Dec 05, 2019
This sales course is customized for the current needs and challenges specific to professionals selling video surveillance and access control...