Hikvision's Hik-Connect Cloud Connects To Vulnerable Devices

Published Aug 15, 2023 13:41 PM

Vast numbers of Hikvision devices are vulnerable, but atypically, Hikvision's cloud service connects to those devices, without forcing any firmware updates, facilitating child pornography distribution and cybersecurity risks.

IPVM Image

There are steps that Hikvision should take to mitigate these issues and force devices to be updated.

Outdated ******** ** ********* *******

**** ******** *********'* ***** ******** ***** connections ** * ********* ***-**-**** *******, including * **** ***** *************** ***************. *** *** ****** *** * version ** ******** **** *** *** the ****** *** *** *** **** any ***** ***************:

IPVM Image

********* ******* *** **** ******** ******* manually ********* ************* ****** ********** ********, ******** ********* ** *** *** UI, ** ******* ********** ****** ***-********** ******. ******* ***** ******* ******* **** and, ** **** *****, ****** ****** access, **** *** ************* **** ****** to ****** ** ******** ******** ** auto-cloud ********.

Hikvision's ******** *************** *** *******, ******* *** ********

********* *** *** ** ****** ******** *************** ***** ****, **** ********* **** *** ******* devices. ***** ***** ** ******* ******** to *** *** ***************, ******* ** the ***-**** ************ ***** ** **** Hikvision *******, **** *** ****** *** to ******* ******* ******* *** *********** but****** *****-*** ********* ******* ** **** fail, ** ********* ** **** **********. **** *** ****** ** ******* with ********** ******** **** ***** *** revisions ******.

Competitor ******* ********

*** ** *** *********** ************* ********* of ******-**-***** ******* ** **** ********/******** vulnerabilities *** ** **** ******* *** remotely ********* ** *** ************ ******* action **** *** **** ** **********.

**** * *** ****** ** ********* to *** ********, *********, *** ***** provider **** ************* ******* *** ******** to *** ****** ******* *** ******** to ************* ******* *** ******* ** allow ***** ** *** ******** ******* of **** **** ******* **** ******.

******* **** *** **** *** ******'* firmware *******, **** ********* "** ** date":

IPVM Image

******** **** **** ******* *** ******* for *******:

IPVM Image

****** ******* *** ******** ******* *** if ***** *** *** ******** *********.

IPVM Image

****** **** *** ************* *********** ******* but ****** *** ********* ******** ********** of ********, *** *******, "***** ****** at * **".

Require ******** ******** ** ***-********** ********

**** ********** **** ********* ******* * non-vulnerable ******* ** ******** **** ***-******* is ***** ******* ** * ******. While **** ***** *** *********** ******* future *************** ** ********, ** ****** be * ******* ***** *** ***** its ***** ********.

***** **** *** ********** ******** ********** friction *** *** *******, ** **** significantly ******** *** ******** ** ***** firmware **** **** *** *********** ******** risk ** ********* *** *** *********.

App ************ **** ******** *** *********

***** ***-******* **** *** ***** ********* firmware ******** ** *** ***, ** would ********* **** *** *** ******* firmware ******** ** ***** ** ****** the **** **** ***** *** ******** updates *** ********* *******.

** *** ******* *****, * **** Camera ******* *** ******** *** **** when ******* * ****** **** *** a *** ******** ******* *********.

IPVM Image

**** ***** ****** ***** * *********** portion ** *********** ** ***** ******** Hikvision *****, ****** ** ***** *** help ***** **** ** *** *** Hik-Connect ** **** ********** *** *****.

Comments