Problems Fixing Critically Vulnerable Hikvision Devices

By Ethan Ace, Published Sep 21, 2021, 10:39am EDT

IPVM has been investigating means to upgrade and fix vulnerable Hikvision devices and has discovered a number of problems in doing so.

IPVM Image

In this note, we look at these issues, including unclear firmware availability, broken firmware update checks, possible undisclosed affected models, and weak notifications by Hikvision, and how they put users at further risk.

Models ******** *** *********

***** *********'* **** ** affected ****** ** **** and ****** **** ******* of *******, ** *** not ** ********.************* ********** ****** ********* to ******** ** *** ********* the ************* ** ** least *** ***** *** listed ** *********'* **********.

****** *** ****** ***** proven ***. * *** root ****** ** ** own ******, ***** *********** on ******* ********* ******** and *******.

** ******** ****** *** indeed **********, ** **** be * *********** *******, as ********* *** *** released ******* **** ******** for **** ****** ***** are **** * *** years ***, ***** ********* ******* ***.

** ***** ********* ** other ****** **** ******** and *** **** ***** handle ************ ******, *** they **** *** *** replied.

Security ******* **** ** ****

********* *** **** ***** about *** ************* ** their *** ******** *** social *****.

**** ** *********'* ******** sites **** **** ********* the ************* ** ***** front *****, *.*.,********* ******,**,**,******, ***. *******, ***** need ** ******** ** Support > ************* ****** > ******** ******* ** order ** **** *******, likely *** *********** ******* to **** *****.

********* ** ****** *** notice ** ******************, *** **** ** clear ********** ** *** severity ** ************ ** users ** ******.

IPVM Image

***** ******* (*.*.,********* ******/********) *** *** ******* it ** ***.

Hikvision ***** ****** ******* ** ******* ******

***** *********'* ***** ************* utility, ***** ****** ***** to ***** *** *** firmware *** ******* ****** firmware ** ****, *** three ****** ******* **** no *** ******** ******* available:

IPVM Image

**** ** * *********** risk, ** **** ** Hikvision's *** ****** *** systematically ******** *** ******** firmware ** ****** ******* of *******. ***** ****** reporting ** ******* ****** could ***** **** ***** with * ***** ***** of ******** **** ***** devices *** **-**-**** *** not **********.

** ***** ********* *** feedback ** *** ***** Config ***** ****** ******** is ** ** ****, but **** **** *** responded.

No *** ******** ***** ** **

******* ***** ******** ****** instructing ***** ** ******** new ******** ** "***** against **** ********* *************", Hikvision ***'* ******* **** shows ** *** ******** available *** ******** ******* affected ******:

IPVM Image

****** **** ******** *********, but **** ********** ******** (prior ** **** **, 2021, ********* ** *** security ******):

IPVM Image

Other ******* ******** ********* / ******** ****** *********

*******, ***** *** ** site ***** ** *** firmware *********,*********'* "******" ********* *** ******** ********* for *** **** ******:

IPVM Image

**** **** ** ********** in ** ***** ** US ********, ** ****:

IPVM Image

*******, ********* *** ************ advised ******* ********** ***-**-****** firmware ** *******, *** IPVM *** **** ******* devices ***** **, ** many ***** *** ** confused ** **** ********. Indeed, ***** ** ******* still ***** **** ****** on *** ******** ********* page:

IPVM Image

** ***** ********* *** clarity ** *** *** US **** **** *** list ******** *** ******* out-of-region ******** ** * concern, *** **** **** not *********.

No ******** **** *********

** **** ***** ********* for ******** ** ***** issues, *** **** *** responded ** *** ******** for *******. ** **** update **** **** **/**** they ** **.

Hikvision ***** ******

******* ** ******* ***** guidance *** **** ******* firmware ********* *** * exploit ** **** ********* is * ******* ******* for *********, ******* **** numbers ** ******* ********** to ******. **** ** especially ********** ** ***** researchers **** *** **** able ********* ******** *** ******* independently, ******* **** ***** experts ********* ***** **** malicious ****** *** ****** to ** **, ** well.

Comments (22)

******** ** **** *****, ethics ******** *****, *** just ***** ** ** too **** ******* ** justify *****. **** ****'** known ***** ** ***** like **** *** * while, *** *** ******** is ** ********* *** un-coordinated ** **** **'* very *************, *** ****'* saying ******* ***** *** quiet ****'** ***** ***** an ***** **** *******.

* ******* *'* **** glad *'* *** ******* around ******** *** ******* this **** ;)

Agree: 3
Disagree
Informative: 1
Unhelpful
Funny

* ******* *'* **** glad *'* *** ******* around ******** *** ******* this **** ;)

******* *** **** *** dealers, ****** / *** joking.....

Agree: 3
Disagree: 1
Informative: 2
Unhelpful: 1
Funny: 9
Agree
Disagree
Informative: 2
Unhelpful
Funny

******, ***** ****** ,)

Agree
Disagree
Informative
Unhelpful
Funny

*** * ********** ********, However **** ****** **** the *** *** ********* plans *** ***** *** they *** ***** ***** as **** *** ** their **** ******* ****** that **** ***** ***'* want *****.

Agree
Disagree
Informative
Unhelpful: 1
Funny

******** *** *********** ********** this ******** ******* **** it ** *** * deliberate ********.

Agree
Disagree
Informative: 1
Unhelpful
Funny

** *** ****, **** news

*** **** *** *** cameras *** ********** ******* and * *****'* **** a ******** ****** *** them ** **** * year. * ** **** they *** **********.

**** **** ** **** always ******* ******* ** potential ****** ** ******* so *** ***** ******* are ** ******** ******** that *** **** ** reached *** ******* *** groups ** ** *** are ** *** *******.

*****'* ********* *** **** but ** **** ******* that *** ******** ** onsite ********** ** *** camera *** ******** ** have *********** *** *********** and *** ** * legitimate ****.

Agree
Disagree
Informative
Unhelpful
Funny

*** *** ******* *** Interlogix *******

** * *********** * firmly ******* **** *** OEMing / ***** *********** should ** ******* ******. It ***** ** ****** impossible *** *** ***** when ********** **** **** arise.

Agree: 3
Disagree: 1
Informative
Unhelpful
Funny

********** ****. * *** not ****** ***** ** Interlogix ****** *** ***** after **** ** *** devices **** *********. **** purchase *** ****. ********** did *** **** **** were ************ ** *** when ***** *** **** did *** ********* **** information ******. *** *** they *** **** **** US. * ***** * will **** ****** ** Australia ** *** ***** firmware *******.

Agree
Disagree
Informative: 1
Unhelpful
Funny

"**** *** **** ************* means ** ******* *** fix********** ********* ******* *** *** ********** a ****** ** ******** in ***** **."

* *** ***** *** impression **** ****'* **** anyone ***** ********* **** anyways ( ******, ******, slavery, ***** ****** ****** and ***). *** ** it **'** ** ******* about *** ** *** or *** *** *** their ***************? ******'* *** rather **** ***** *** removal *** *********** **** another "********" *****?

Agree: 2
Disagree
Informative
Unhelpful: 5
Funny

*** ************ *** ***** a **** **** ****** about ******** ****** ****** should ** ******* ** remove / ******* ********* & ******* ** ***** opportunity.

**** **** **** *** users ** *** **** the ****** ** ******** fix *** ***** ** you **** ** **** you *** **** *** gear **** ** ** site.

* **** **** ****** IPVM ** ********** *** pro ***** ***** ******** within *** ******** ******* that **** ****** *** options. * ********** **** that **** ** * whole **** * **** job ********* *** ******* wants & ***** ** their ***********. ** **** ways **** ** ***** what *** ** *** US & ***** ** Australia ****** ** *****, but ****'*.

Agree: 1
Disagree: 1
Informative
Unhelpful: 1
Funny: 2

"**** **** **** *** users ** *** **** the ****** ** ******** fix *** ***** ** you **** ** **** you *** **** *** gear **** ** ** site"

**** **** **. ***** are ***** ***** ***, less *******-**** ****** ********* available **** **** *** any ******. *** *** their ******** **** **** deemed ** *** **** it **** *********** ********** end ***** ******* *** make ***** ********** **** secure *** *** * national ******** ****** ***** the *** ******* ** are ********** *** ****** end ***** *******. ** away **** *** ********* equipment, **** *** ********* hit ***, ****** **** taking * **** ***** hit *****. **** ******** how *** *** ** daily, *** ** *** to ***** ********* ****** to "***" *** **** equipment? **** *** *** running *** ** ***** of *** ***** ** speak ****. **** **** both. **** ****.

Agree
Disagree: 1
Informative
Unhelpful: 1
Funny: 1

* **** ** ***** it ** ******* **** recognizes **** **** ** installed **** ****** ** ripped *** ******** ********. Our ********* ******** ** 2 ***** **** * cost ******* ** $*.** just *** *** *******.

Agree
Disagree: 1
Informative: 2
Unhelpful
Funny

"* **** ** ***** it ** ******* **** recognizes **** **** ** installed **** ****** ** ripped *** ******** ********. Our ********* ******** ** 2 ***** **** * cost ******* ** $*.** just *** *** *******."

* ****** **** *** cost ***** ** ** $1.5M ***** ** *********, potentially ******** ******* (**** with **-****** "*****" ********) sourced **** **** ***** mfg, ********* **** ********* against **** ******* *** it's **********. * ******* a ****** **** ******* then $*.**. ****'* ** hoping **** *-**** ******* plan ***** *** *** your *******. *** ** all **** **** ** said ***** ****** . What *** **** ******* doing *** *** **** 2 ***** **** *** preaching ***** *** **** empire?

Agree
Disagree
Informative
Unhelpful
Funny

**** ********* *** *********** cost *** * ******* HOWEVER ** ********* ******* the ********** ** ** event **** ** *** describe * ****** *** by ********* ***** ******* on ********** ******* *******. Patching ***** ******* ***** be ****** ***** ********** the ******* **** ** prem ******* ***** ***** impact *** ******* *** building ********** ******* ** the ******* *******. ** the ****** ** **** a ******* ******** ******* would ** ******* *** certainly ***** *** ** used ** * ****** under *** *******.

Agree
Disagree
Informative
Unhelpful
Funny

******: ******* ******* **** responses ** *******? *** are ******** * **** line ** *** ***** of *******…

Agree
Disagree: 1
Informative
Unhelpful: 1
Funny: 1

*** *** *** ******* to **?

Agree
Disagree
Informative
Unhelpful
Funny

"*** *** *** ******* to **?"

*'* ******** **, *** in *********, ******* ** us ** "*******" ****** to "******" **** ** opposed ** "*******" **** (libel), ** ** *** memory ******. * ***** they ***** ** *************** (referencing ******** *** ****) nowadays ***** ** **** make ** ***** *** definitions (*'* ****** ** it ******). ** *******; disregard ** * *******.

***- ******** ** **** segregated ****** *******; ** the *******/***(*) **** "***" way ** ******** ******** traffic ** *** ******** (i.e. *** ******* ** other **************)? ** **, they *** *** ****** from ********* **** ** if *** ** **** admins *** ** ******** with *******, ********** ** using ********* ***/*******...

Agree
Disagree
Informative
Unhelpful
Funny

"*** *** *** ******* to **?"

***, ***-***, *** *** quotation ****** ** *** toolbar ******* ** ***** quotation *****:

IPVM Image

*. **’* *******

*. **’* *******

*. ** ****** *** to **** * *** times ** * ***** before ******** ******** “**’* that ***”.

Agree
Disagree
Informative
Unhelpful
Funny

'

"*** *** *** ******* to **?"

***, ***-***, *** *** quotation ****** ** *** toolbar ******* ** ***** quotation *****:

IPVM Image

*. **’* *******

*. **’* *******

*. ** ****** *** to **** * *** times ** * ***** before ******** ******** “**’* that ***”.

'

"

****** *** *** ***

Agree
Disagree
Informative
Unhelpful
Funny

Agree
Disagree
Informative
Unhelpful: 2
Funny: 8

***** ** **** ******? :)

*******:*****’* ************* *********

Agree
Disagree
Informative
Unhelpful: 1
Funny: 2
Read this IPVM report for free.

This article is part of IPVM's 7,250 reports and 966 tests and is only available to subscribers. To get a one-time preview of our work, enter your work email to access the full article.

Already a subscriber? Login here | Join now
Loading Related Reports