Hikvision Happy With Bad Security Unless Hit With Bad Press

Author: John Honovich, Published on Aug 28, 2017

Hikvision is happy to have bad cyber security unless they are hit with bad press, as we detail inside.

When you look at the pattern of their behavior, it is clear that anyone concerned about cyber security is taking significant risks with Hikvision. Hikvision's marketing claims to care but Hikvision's actions show otherwise.

#1 - Emailing Admin Passwords Plain Text

Hikvision has been emailing iVMS-4200 admin passwords in plain text. And they do not even attempt to verify who requests it, anyone unauthorized just presses a button on the client and Hikvision will immediately email the admin password in plain text, e.g. how they responded to one of our requests:

Today, Hikvision finally did something.

Why? Because IPVM published Hikvision VMS Password Recovery Vulnerability.

Hikvision emailed its dealers a [Special Bulletin] Security Structure Update to iVMS-4200. That 'structure update', which they did not even explain, was to stop allowing people to request admin passwords emailed in plain text.

And this is, unfortunately, commonplace with Hikvision.

#2 - Cracked Security Codes

Get Video Surveillance News In Your Inbox
Get Video Surveillance News In Your Inbox

Hikvision has known for more than a year that its 'security codes' to reset its IP cameras and recorders were cracked and available as unauthorized online 'tools'. Many of their recorders still had no firmware upgrade fix available for this crack.

On August 8, 2017, IPVM published Hikvision Security Code Cracked.

Hikvision responded on August 10th with a [Hikvision Special Bulletin] Password Reset Update. The convoluted post misled their dealers, dismissing "so-called Hikvision 'security code' being 'cracked'". But that is what Hikvision called them - 'security codes' as shown from their own documentation:

And Hikvision did not have enough respect for their dealers to let them know that working generators for these security codes are still available online.

Worse, Hikvision is still allowing these unauthenticated resets with a new generator that they hope will not get cracked.

#3 - Hikvision Backdoor

On March 5th, 2017, a researcher announced a Hikvision camera backdoor (who later DHS gave credit to in Hikvision's worst 10.0 vulnerability advisory).

On March 10th, we emailed Hikvision telling Hikvision we planned to release an article on Monday, March 13th. And on Sunday, March 12, Hikvision again issued a [Hikvision Special Bulletin] Update on Privilege-Escalating Vulnerability. Again, Hikvision obscured the risk with the vague statement "obtain an unauthorized escalated additional user privilege". It was only until the DHS advisory was released that the public learned the true severity of the vulnerability.

#4 - Hikvision Defaulted Devices Mass Hacked

On March 2, 2017, IPVM published Hikvision Defaulted Devices Getting Hacked after weeks of ongoing reports from Hikvision dealers saying that their systems had been hacked. Hikvision knew well that this was happening but they said nothing to their dealers.

Until IPVM published, and then Hikvision immediately issued another [Hikvision Special Bulletin] Defense Against Scripted Application.

Public 'Proclamations'

Hikvision's poor practices occur despite their claims that Cisco 'recognized' their cybersecurity or that they hired Rapid7 to do vulnerability assessments. It is hard to imagine that Cisco or Rapid7 would approve of emailing admin passwords in plain text. It, evidently, is not so hard to imagine Hikvision accepting such practices.

Lessons Learned

These incidents show that Hikvision's actions fall far behind their marketing claims and even their communication to their 'partners' is focused on doing damage control and spinning bad press.

If you are serious about cyber security, you cannot seriously use Hikvision.

5 reports cite this report:

Hikvision Admits Backdoor 'PR Issue' on Oct 24, 2017
Hikvision is admitting a problem. The backdoor itself is evidently not the problem for them. The problem, according to Hikvision, is a public...
FLIR Thermal Camera Multiple Vulnerabilities, Patch Released on Oct 03, 2017
Multiple cyber security vulnerabilities exist in FLIR thermal cameras, which have not been fixed, despite being reported months ago. UPDATE- FLIR...
80+ OEMs Verified Vulnerable To Hikvision Backdoor on Sep 22, 2017
Over 80 Hikvision OEM partners, including ADI, Interlogix, LTS, and Northern Video, have been verified as having products vulnerable to the...
Hikvision Backdoor Exploit on Sep 03, 2017
Full disclosure to the Hikvision backdoor has been released, allowing easy exploit of vulnerable Hikvision IP cameras. As the researcher, Monte...
Fortune 500 Company Bars Dahua and Hikvision on Aug 30, 2017
A Fortune 500 company has barred Dahua and Hikvision cameras from a large RFP due to cyber security concerns, IPVM has confirmed with the...
Comments (30) : PRO Members only. Login. or Join.

Related Reports

No GDPR Penalties For UK Swann 'Spying Hack' on Nov 20, 2018
The UK’s data protection agency has closed its investigation into Infinova-owned Swann Security UK, the ICO confirmed to IPVM, deciding to take “no...
Axis: "No One Wants To Buy A Camera" on Nov 09, 2018
Axis has, in its own description, made a bold declaration: The industry is changing so rapidly that the following statement might seem bold but...
Winter 2019 IP Networking Course on Nov 05, 2018
This is the only networking course designed specifically for video surveillance professionals.  Lots of network training exists but none of it...
HID: Stop Selling Cracked 125 kHz Credentials on Nov 05, 2018
HID should stop selling cracked 125 kHz access control credentials, that have been long cracked and can easily be copied by cheap cloners sold on...
"New Zealand Govt Uses Chinese Cameras Banned In US", Considers Security Audit on Oct 12, 2018
Newsroom NZ has issued a report: "NZ Govt uses Chinese cameras banned in US": This comes after the US federal government banned purchases of...
China Hacks Video Servers Causing Uproar on Oct 05, 2018
An incident causing an international uproar is hitting home in the video surveillance industry as a Bloomberg report, "The Big Hack: How China...
Genetec Takes Aim At 'Untrustworthy' 'Foreign Government-Owned Vendors' on Sep 24, 2018
Genetec is taking aim at 'untrustworthy' 'foreign government-owned vendors'. This is not a new theme for Genetec as nearly 2 years ago, Genetec...
Hikvision FIPS 140-2 Cybersecurity Certification Examined on Aug 27, 2018
A week after the US government passed a law banning Hikvision, Hikvision announced it had obtained a FIPS 140-2 certification from the US...
Sony Gen 5 IP Cameras Critical Vulnerabilities on Jul 26, 2018
Cybersecurity vulnerabilities remain prevalent in video surveillance devices. Now Talos researchers have discovered multiple vulnerabilities in...
Hikvision Covers Up Racial Profiling And AI Error on Jun 25, 2018
Faced with global scrutiny, led by the US government-funded Voice of America (VOA), Hikvision has covered up evidence showing their racial...

Most Recent Industry Reports

The 2019 Video Surveillance Industry Guide on Dec 10, 2018
The 300 page, 2019 Video Surveillance Industry Guide, covers the key events and the future of the video surveillance market, is now available,...
Multi-Factor Access Control Authentication Guide on Dec 10, 2018
Can a stranger use your credentials? One of the oldest problems facing access control is making credentials as easy to use as keys, but restricting...
Top 2019 Trend - AI Video Analytics on Dec 10, 2018
160+ Integrators answered: What do you think the top industry trend will be in 2019? Why? AI / video analytics was the run-away winner with...
AV Tech Company Profile on Dec 07, 2018
Taiwanese manufacturer AV Tech's revenue declined ~70% since 2012. Planning a comeback, AV Tech spoke to IPVM about their opportunities and...
Ubiquiti $79 Flex IP Camera Tested on Dec 07, 2018
U.S. Manufacturer Ubiquiti has released a 1080p, integrated IR IP camera, selling it directly for $79, making this one of the least expensive IP...
Infinova's Xinjiang Business Examined on Dec 07, 2018
As pressure mounts for companies to stop doing business in China’s Xinjiang region amid a severe human rights crisis, IPVM has found Infinova sold...
Akuvox Intercom Profile on Dec 06, 2018
Akuvox, a Chinese manufacturer of VoIP products, is expanding heavily into Video Intercom products with disruptive pricing targeted for commercial...
Sublethal Camera Gun Examined on Dec 06, 2018
Sublethal is a South African company that manufactures a remotely-controlled, camera-enabled gun called the Boomslang, which is Afrikaans for tree...
UK ICO Denies IPVM GDPR Complaint Against IFSEC, Decides Each Exhibitor Responsible on Dec 06, 2018
The UK Information Commissioner's Office (ICO) has denied IPVM's complaint against IFSEC for misuse of facial recognition. Each Exhibitor...
VMS Live Monitoring Shootout - Avigilon, Dahua, Exacq, Genetec, Hikvision, Milestone, Network Optix on Dec 05, 2018
Viewing live video is the first interaction and most common task most users have with a VMS. Who does it best and worst? Who offers the most...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact