Hikvision IP Camera Critical Vulnerability 2018 Disclosed

Author: IPVM Team, Published on Aug 16, 2018

The same day that the US government passed a prohibition on Hikvision cameras, Hikvision disclosed a critical vulnerability for its IP cameras.

However, while the US government is concerned about the PRC using Chinese government-owned Hikvision for cyberattacks, this vulnerability is clearly not related to the Chinese government.

On the other hand, it is a critical vulnerability and the potential for damage is high. With Hikvision's continued recommendation to port forward and its mass OEMing, this means a vast number of products, both Hikvision branded and via OEMs such as Interlogix, LTS, Anixer/Northern, Panasonic/Advidia, etc. will be impacted.

In this note, we review the vulnerability disclosure and the potential impact.

*** **** *** **** ***** ********** ****** * *********** ** ********* *******, ********* ********* * ******** ************* *** *** ** *******.

*******, ***** *** ** ********** ** ********* ***** *** *** using ******* **********-***** ********* *** ************, **** ************* ** ******* not ******* ** *** ******* **********.

** *** ***** ****, ** ** * ******** ************* *** the ********* *** ****** ** ****. **** *********'* *********************** ** **** ************* **** ******, **** ***** * **** ****** ** ********, **** ********* branded ****** **** **** ** **********, ***, ******/********, *********/*******, ***.**** ** ********.

** **** ****, ** ****** *** ************* ********** *** *** potential ******.

[***************]

Vulnerability ********

*** ************* *** ********** ** ******* ***********, *** ** ******* * ******* ** **** *** ******* IoT ************ ************* (*** **** **** *******).

********* -********* ******** ******** ****** ** **** *************,****'* ******** **** ** *********'* *****************-****-**** ******. ** ********* ********* *** *************:

* ****** ******** ************* ** *** *** ****** ** **** Hikvision ** ******* ****** ** ******** ** **** * ********* crafted ******* ** ******** *******. *** ** *** ************ ***** validation, * ********** ******* *** ******* ****** *** **** **arbitrary **** ********* ** ***** *** *******. [Emphasis Added]

*** **** ****** ** **** ********** ** ***** ** ******. Exploiting *** ************* ****** ******* ** ****** **** **** *** device ** ***** *** ******.

*** **** **** ***** ** * ******** *.* / **.*.

Models ******** *** ***

**** ** ****** ****** *** ******** *** **** *** ***, according ** *********.

********** / ******** ****** (**** *********'* ******):

  • *********** ****** (**-*******, ********** ****** “***** **** *.***”)
  • ***** **** (**-**********)
  • ***** ****** *********** ***** ****/****** (**-*******)
  • ***** *** ***** ****** **** (**-****/*/*/* *** **-****/*/*/*)

*** ********** / *** ******** ****** *******:

***** ***** ****** ****** (****** ***** **** ***, **-********), *** smart ****** ****** (**-*******), ******* (**-*******), ********** (**-*******), ****** (**-****/***/******), thermal (**-******)

****: ********* *** *** ****** * **** ** *** ********** devices. ** **** ******* **** **** ** **** ******* *** users. ** *** **** ** ********** ** **********, *** ** know ** *** ******** *** ** **** ******.

No ********* ******* *** / ****** ** ****

********* ******* ** *** ** ******* **** **** ** ******** later **** ****.** **** *********:

********* ******* ** *** ********* ************* **** ** ********* **** the ** **** *** *********, ******** ****** **** *** ********.

**** ********* ***** ******* **** *** ******** *** ***** *********'* fractured ******* *** ******** ****, ****, ** *** **** ******* will *** ** ******** ** ****. **** *** ********* ******* are ********, *** **** ******* ******* ****** ********* ** *** various ********* *** *** ** ******* **** **** *** **** patched.

Positive *** ********* - ***** ************

********* ****** ** ********* *** ********** **** *****. ********* ***** have ****** ***** ****'* ** *** ****** *** **** ** delay *** ** ***. *******, ********* ********* ** ************* ***** of ****'* ****** **********.

Comments (32)

*** **** ** **** *** **....****** ** **** *******'* **********??

****, *** ********** **** ********* ** **** **** *** ** because **** **** **** *** ***** ** ** * *** months. **** *******, ***** ** *** ***** *** ***** *** tester, **** ***** **** ***** ********* ** ******* **** **** of ** ******** ***** **.

**** ***** ** ********** ** ********* ********* **** ******** *************** Rapid7, ***** *** ***** ***** ***** ************* ***** *****.

******** ****** **** *** ***, *** **** ** *** ******* happening **** *******/****** ** *******/**********.

******** * ********** ***** ** *********, * *** **** ****** as **** *******: ****'* *** ** ****** ** ****! (***, but ***** ****** **** ************ **** **** *****) ;-)

************, ***'* ****? =]

***'* *** * ** **** ********* ** ****. ******* *** their ****** ***** ****** ************* * ********, ********* ****** *** too **** ****** ** **** **** ** ***** *******. ** is ****** ******** **** ***** *** ****** ** ******* ******** buried ** ***** ******* ******** *** ********, **** ******* ** be **********.

************ *** *** *******-**** ***** ***** ***** ** **** **** "myth" ** *** ******** ***** ******** *****.

*********, ****'* **** ****:

Related image

**** ******* ***** ** **** ** *** **** ********. ***** Hik-specific, ** ***** **** ** ******** ******* ** **** ***** last ****.

**** **** * **** **** *** ***** ************ *** ****** as ******.

********* *** ** ********* *** ********** **** *****. **** ** how *** ****** ****** **** ************. ** ******* *** *** handling ****** ********* *** *************.

** ****,** *** ******* ***** ********* *** *** **** ** Genetec ** *** ***** ***-******* *******. *** ** ****** ** rhetoric **** *****...

*** *** *********. **** *** **** ******* **** *** ******** all *** ******** ** *** *** ** *** *** *** your ******* ** *** ** ** **** ****** ********* *** make *** ******** ******* **** *******. *** *** ****** ** see **** *** **.* ****!!!. *** **** "*********" ****** ** completely ****** **** *** *** ******** *** *** * ****!

******** ** *** *** **** **********?

* **** *** * **** *** * *** ******* ** trolling.

** *** "****" **** **** ******* * *** ******* **** favorite *****, *** ** ****** * ******:

*: ****** **** *********. ***** *** **** ** *** ** articles (*** ***'* ** * **** *** *** *** **** time):

**** **: * ** ***** ********* ***** ****, ** **** it **** *****

**** **** *: * ************* (***** ** *******), * ******* test (**** * ******** *******), * ******** ******* ***** *** (obviously ****** ** ****), * ******* ***** ******** **** **** attendance (********* ** *********)

**** **: ** ** ***** ********* (********* *** *****)

**** **** *: * ****** ********, * ******** ********, * is ***** * ******** / ******* ******, * ******** *** article (********* ****** ** ****)

** **** ** **** *****, **** ********* ** *** **** 5 ******* **** *** ***, ***** ** ** ******* ******** about **** *** ******** ***. ***** ****** **** *********/******* ** not ****? ***

*: ****** **** ***** ********, ** ** *** ***'* **** any ******** *********** ** **** ****, **** ******** *** ****** suspend ** ***** **** ********** **** **** ******** ************ ** in *******.

*** ******* **** ** ******, **** ** *** ****.

** ***** ** ** ********* ********* ******* ***** * *************, do *** ***** *****, ***** **** ****** ********. ** ***** you **** ********, *** * ********** ***** *** *** * serious ***. *** ****** ***** *** ****.

**** **: *

**** **: **

**** **** *: *

********. *** *** ******* **** ***** ******?

*** * ********** ***** *** *** * ******* ***

****** **** ** *********** *****?

*'* ****** ************ ***. *** ***** ***** **** *** *** worrying ***** ** ****** ******* ******** ***** **** ******* ********* :)

**** * **** ***.

**** * **** *** ***!

*** ****** ** ** ***** ******* ** ******** **** *********, ma'am.

** **** *** ****** ******** ** ******* *** **** *** hides ****** *** ***** ** ***********. **** ******* ** **** that **** ** **** ****** *******.

**** ** ****** **** *****'* **********:

*) ************* **********

*) ***/*** *********** ** **** ** ****

*) ****** ****** ** **** **** *******

** **** *** ****** **** * **** ****, *** ******* to **** ** **** ******** **** *** ********* *******.

** *** ***** ****. *** *'* * *****, *** ********** my **** ******* ******* ** ***** **** *** *** ****** taking **** ***** ** ****** ******* ** ********* ** **** industry.

** *** **** ******** ***** ******?

**, * ***** **** **** ***. ***** *** **** *********? Or **** ***** ****** *** ********?

***, * **** ** **** *** *** **** * *** and ***** ** ** ****, *** ********* * *** ****** a **** *** ** **** ***** ***** ** ** ********* it?

***, **** ** *******, *** * ***** *** ****** **** disclosed, ********** **** *** *** * *****, ******* *** **** appear *** **** ********** **** **** ** *** **** ** here *** **** ******** ********* ****** ***** ***** ****** *** hide ****** *** *********** *****.

** *** ****, *** **** **** *** *** ******* *********** distressed *** **** ************ ** ******* *** *** *****. ** far ** ** *********, **** *** *** **** ****, *** feel **** ** *** ** *** ******** ********* *** * will ** ***** ** ****** ****.

* ***** **** ** *****, *** ****'* ******* *** ******** comment. **** ***** ********* ******!

* ********* *** *** ** ***** "***" *** **********.

***** *** ************ *** *** ********* ** ******? ***** **** been ** ****. *'** ** ***** ** **** * ******** non-troll ***********.

**** ***** ** * **** ****** **** ******* *** *********** button.

** *** **** ********* ** ***, *** **. **** ** share **** **** ***'* ** ******? **** ** ** *** team. **** *** **** **** * ****** ** ***** *** credibility *** ***** *** **** ** **'* ********.

******* *********** *** **** ***** ***** ** **, ** ******* a ***** **** *******'* ** *******.

** *** *********** *** **** #*, *** **** ******* **** and **'* ******* *** ****** ** *** ****** **********. ****'* not * **** *** *** ** **** ** ** ******.

***** ** *** **** *****, ** * **** **** ** multiple **** *******: ** *********** ** ****** ******* ***** *** ***** ** *********** *******. Further ********** ** **** ***** ** ***** ** *** *******. Undisclosed ******* ** *** ***** ******** ** ****.

** ****** ***** ***************** **** ****** ********* *************, ****, ** *********'* ********, **** free. **** ** ********** **** ******* **** *** *****.

****, ************* ** * ************ ******* ** * ******* ******** such ** **** ***** ** * ***** *** ***** ******** and ***** ******* ******** ******* ********* ************* *** ************* *************, as **** ** ***** ******* ********** ** ** ***** ** operating ** **** ***** ** ******* *****. ****** ******** ***** of ****, *** ******* **** ********** ********** (****) (**)****/***, ***** is * ********** ** ** *** ** **** ********** *** privacy *** *** *********** ** *** ******** *****. .*** ********* is * **** ******.

****, ***** *** ******** **** ******** *** **** *** ********** on *** **** ************* ***** ** ** ***** ** **.

***** *** *** *** ***** ************ **** ** ****** *** this ********.

***** ******

************** **********

** **** ***** * ***, ********* ********* *** ****** * fix ****** *** *********.

*** ***** **** *** ** *** **** ******* ** ***** using **** ***?

*** ***** ** *******. *****, *** ** *** ******* ** near *** ******* ****** ************. ******* ** ** ***** *** a ****** ***** ** *** ******* *** ************ ***** ** headline ****.

****** ** *** ******. *** ** ********** ******* ***** ***** cyber ******** *******. ***, * **** *** ***** **** * vulnerability *** ****** ******, ******* ** * ******* *** **** of ****** ** ****** ***** ******** **** ****** **** *** and *** ******* *************** **********. ** *** **** *** *** to *** ***** *******, **** ** ********** ** ***** ***** need ** ** *******, ***. *** **** ** *** ***** own ****. ** * ******* *** **** *********, *** *** they ******* ***** **** *** *****? * ** ******* **** for ******** ******* *** * ******* ********* *** ******** ******** quickly, ***** ** * **** ******* *** ****.

****, (* **** **** **** *** **** ******** ******), *** Hik **** **** ********** *******. *** ***** ****** **** **** a ******* **** *** **** *******. *** ****** **** ** look ****.

*******, ** *** *****. **** **** ******** * ***** ** 8.9. *****, *** ** * ******* **** ** ** ******* on ***** ******** ****** **** *** **** ***** **** ******* vulnerabilities? (*** ***, * **** **** ***** ***** ********* **** are ******* ***** ***** **** *** *******, **** ** ****, Dahua, ***. * ***** **** ** ****).

** * ******* *** **** *********, *** *** **** ******* these **** *** *****?

***** ** ****:********* ********,***+:

* ***'* ******* **% ** **** ********* ** *&* ** sustainable ** *** ********** ******.

********* **** *** ****** **** **** ***** ** "*&*" ** it ** **** ** **** ** **** *** *********** ** in *** **** *** **** ******* ********** ********* **.

******* ******* *****. * *** * ******* ***** **** ******'* repair ******* **** ** ***** *** **, *** ******. ** they *** *********, ** ****** *** ****.

* ***'* ****** ******* ** *** **** ********* ** *&* colleagues **** ***** ******... ** **** ** ***** *********, ** you **** **** ****** ** *********, *** **** **** **** amount ** ************* ******?

* **** ***** **** * *** *** ** ** **** reusing *** ****. *** ***** ***** ** **** *****, *** to ***************, ****** ** ***** ****** ****, ** ****** ** get **** **** ****-***, **** ***** ***** **** *** **** a *** ****** **** * *** ** *** * *** back ***.

** ****.

* **** ** ** * *** ** *********** *** ******* to ** ****, *** **** ** *** * ******* ***** a ***** ***** ** *********** *** *********...

*** ***** **** *** ** *** **** ******* ** ***** using **** ***?

* ******** ***** ** *** **** ********** *** *'** *********. ******* ******* *** *** ** *** business ** ******** ******* ***** *****, ** ** ** *** a ********** *** ** ***** * *************.

*** ****** **** **** ** **** **** ********* ** ** 90 ****. ********* ** * **** ***** *** ****** **** lots ** ****-*********, ******** ********** *******, ***** ***** *** ********** is **** **** **** **** ******* **** *** ****** ***** this ****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Most Recent Industry Reports

Alexa Guard Expands Amazon's Security Offerings, Boosts ADT's Stock on Sep 21, 2018
Amazon is expanding their security offerings yet again, this time with Alexa Guard that delivers security audio analytics and a virtual "Fake...
UTC, Owner of Lenel, Acquires S2 on Sep 20, 2018
UTC now owns two of the biggest access control providers, one of integrator's most hated access control platforms, Lenel, and one of their...
BluePoint Aims To Bring Life-Safety Mind-Set To Police Pull Stations on Sep 20, 2018
Fire alarm pull stations are commonplace but police ones are not. A self-funded startup, BluePoint Alert Solutions is aiming to make police pull...
SIA Plays Dumb On OEMs And Hikua Ban on Sep 20, 2018
OEMs widely pretend to be 'manufacturers', deceiving their customers and putting them at risk for cybersecurity attacks and, soon, violation of US...
Axis Vs. Hikvision IR PTZ Shootout on Sep 20, 2018
Hikvision has their high-end dual-sensor DarkfighterX. Axis has their high-end concealed IR Q6125-LE. Which is better? We bought both and tested...
Avigilon Announces AI-Powered H5 Camera Development on Sep 19, 2018
Avigilon will be showcasing "next-generation AI" at next week's ASIS GSX. In an atypical move, the company is not actually releasing these...
Favorite Request-to-Exit (RTE) Manufacturers 2018 on Sep 19, 2018
Request To Exit devices like motion sensors and lock releasing push-buttons are a part of almost every access install, but who makes the equipment...
25% China Tariffs Finalized For 2019, 10% Start Now, Includes Select Video Surveillance on Sep 18, 2018
A surprise move: In July, when the most recent tariff round was first announced, the tariffs were only scheduled for 10%. However, now, the US...
Central Stations Face Off Against NFPA On Fire Monitoring on Sep 18, 2018
Central stations are facing off against the NFPA over what they call anti-competitive language in NFPA 72, the standard that covers fire alarms....
Hikvision USA Starts Layoffs on Sep 18, 2018
Hikvision USA has started layoffs, just weeks after the US government ban was passed into law. Inside this note, we examine: The important...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact