Hikvision Audit Admits iVMS-4200 Auto Connects to China

Published Feb 10, 2022 15:21 PM

Hikvision submitted a cybersecurity audit to the FCC revealing the widely used iVMS-4200 application automatically connects to servers in China.

IPVM Image

The audit found that these "connections [were] associated with identifying software updates" and that "corrections will be included in a future update of iVMS-4200." Neither the auditor nor Hikvision commented on when these connections to China will be corrected.

iVMS-4200 is a free client widely used for Hikvision customers to view and manage video, which connects to and has access to many cameras in systems.

**********

********* ******** ************* ** "********* ************* ********** ******," which *** ***** **** *** *** in ********. **** ** ******** **** their******** *** ****** ********* ** *******, ***** ********* ****** **************.

********* ********* ********* "************ *********" *** the ******** *******, ***** ***** *******, its ******** "*** **** ** ******** the ********** ** * ********** *********** on ********* *********."

*** ******** **** *** ******* **** information ********* *** *** **** ** be ******. *** * ******* ** Hik-Connect, ********'* ***** ************ ***, *** heavily ********.

*** ********** ********* **** ********* ******* "present ** ********* ********." *******, **** identified ****-**** ******** ** ******* ** China, ********* ******* **** ***-*******'* ************** hashing *********, ********** ******* ****** **** Hikvision ****, *** ******* "******** *************** that ********* ***** ********* ** ******* enhance ***[**] ************* *******."

iVMS-4200 ************* ******** ** *****

*********'* ****-****, * ******-**** ******, ******* "multiple *********** ** ******* ******* ** China" **** *******:

**** ******* ****-****,FTI ********** ******** *********** ** ******* ******* ** *****. These connections occur at time the application is started by the user. [emphasis added]

**** ******** **** *** **** "******" causing ************* "** ********* ******* ******* of *** ******** ************ ******":

***’* ****** **** ****** ** *********’* supporting ******** ********two ****** ** **** that caused communication to an outdated feature and to Hikvision ******* ******* ** *** ******** ************ ******. [emphasis added]

*** **** *** ****-**** *********** **** "caused ** ****** ********** ** ******** functions **** *** *** **** ***** removed," ***** **** "********** **** *********** software *******."

US ** ******** **********

*** ** ********** ** ******* ******* raised ******* ******** ***** ****-****,*********:

**** ********** ******** *****-***** ************* ***** has ********* *********** ******** *****.

**** ********** *** ******** **** **** the ** **** **** ******* (***)

*** *********** ******* ****-**** ** "**********. **** ***** is *** (*********) ********* ** ** used ***** *** *************."

PRC ***** ******* ********* *** ** ***-*******

************, *** ***** ***** **** ** Hik-Connect ******* **** *** ********* *******, Chinanet, *** *******:

IPVM Image

*** ****** ***** ****, ****** *** iVMS-4200, ***** *** ********* *** ***** non *** ***** *******, ****** ** this ** *** ********, **** ** video ***** ** ******* **** *** of ***** ******* ** ******** ********.

Hik-Connect ******** ********, ************** *************

********* ***** ** ******** **** ** the ******'* ******** ********* ***-*******, ***** cloud ******** ***:

IPVM Image

********* *** *** ******* ** *** request *** ********** ***********. *******, *********'* request *** ************ ********* ** *********** in *** ****** ********** ****** *** reason ** *************. *** *******:

IPVM Image

** *** *** ** *** ******, FTI **** ***-******* **** ** ************** protocol "***** ** **** *************** *** is *** ***********":

*) ***-******* **************: ****** *** ****** code ******, *** ********** **** *** MD520 ************* ******* ********* ** ***** used ** ************ ********.MD5 ** ***** ** **** *************** *** ** *** *********** ** ** **** *** ************** **********. FTI ********** ************ * ********* ******* *********, such as SHA-256 with salt as a replacement to the current MD5 hashing algorithm. [emphasis added]

"Outdated", "****-******" ********

*** ***** ********* **** "******** ****-****** packages **** ******** ******** ** **** devices" ***** *** ********** **** "******** publicly ***** ***************." **** *** ***** are *** ***** ** ***** *************** ********** ** ********* ******** by *** ********** ******** ************* ******** ******** ****.

*******, *** ****** ********* **** **** they **** ******** ** ***** ** mitigate ***** ***************, *** **** *** validated *********'* *********:

********* ********* **** *** ****-****** ******** packages ** ********** **** *** ****** software *** ******** *** *********** ** a “****** *****” *** *********** ************ controls ** ******* *** ********* *** mitigate *** ******** ***** ***************. ***’* vulnerability ********** ***** ********* **** **** of *** *************** ******* ** *** outdated ******** **** ******* ** *** devices ******* ********** *********’* ********* *** contradicting *** *********** **** ******* ********* in *** *****-***** *** **** *********.

*** **** ***** ***** ****** **** "use ** ******** ********** *********" *** "IP-forwarding *******".

Cybersecurity ***************

*** ******* ******* *************** *** ********* to ******* *** *************. **** *******, that ********* ****** *** ************** ******* algorithm *** ***-******* ** ********* ******* known ***************.

***** *************** **** ** ****** ********* software ******* *** *** *******, ****** than **** ******** ****, *** **** Hikvision ******* ************* **-****** ***** ************** in ******* *********.

Hikvision ** ********

********* *** *** ******* ** ****'* request *** *******.

Update (**/**/**): Hikvision ******* ****-**** ******* ********** ** *****

********* *** **** **** ******* *** iVMS-4200 ******** ******* *********** ** ***** in ** ****** ******** *** *, 2021 ****** ********** *** *** ****** on *** **, ****.

*** *** ******, ***** ********* ********** submitted, **** ** *** ******** **** "corrections **** ** ******** ** * future ****** ** ****-****." ** ***** Hikvision *** ******* * ***** ***** to *** *********** ** **** ******, and **** *** *** ******* **** any ************** ** *******:

IPVM Image

Comments (15)
UM
Undisclosed Manufacturer #1
Feb 10, 2022

**** ***** **********?

********** ** *********'* ********** ***** *** that ** $**,*** ****.

(3)
(3)
(4)
CH
Conor Healy
Feb 10, 2022
IPVMU Certified

*** ***** **** *** ******* **********, and *'* *** ***** ** **** has **** ****** *** ******* *********** to *****.

AM
Andrew Myers
Feb 10, 2022

*******: *****'* ** ********* **** ** the "***-******* ******** ********, ************** *************" section:

** *** *** ** *** ******, FTI **** ***-******* **** ** ************** protocol "***** ** **** *************** *** is *** ***********":

*** ** * ******* *********, *** an ************** ********.

---

*** *** ***** ******** ***** **** is ******** *******, *** * ******** FTI's ***********.

*) ***-******* **************: ****** *** ****** code ******, *** ********** **** *** MD520 ************* ******* ********* ** ***** used ** ************ ********.MD5 ** ***** ** **** *************** *** ** *** *********** ** ** **** *** ************** **********. FTI ********** ************ * ********* ******* *********, such as SHA-256 with salt as a replacement to the current MD5 hashing algorithm. [emphasis added]

***-***??? ****'* * **** ******** **** over ** ***** ***. ***'** ******** to *** ****** ** ******** ********. Even ** ****, ****** **** ********* to ******. ** *** ***** **** practice ******** **** ****? ****** **** changed ********* ****.

*** **** **** * *** ***** of ***** ***-*** ***'* ***** *** idea ** ** **'* *** **** to **** *********... ** ***** **** why ***** **** ** ******* ***** salting? *** *** **** *** ***? If ***'** ******* * ******, *** bcrypt/Argon2id. ** ***'** ***, **** ** makes ** ***** ** **** ***** salting ** ********* **** ***. ****** way, ***'* ************** ** *** *****.

** *** ********* ****, "*** ** not ***********" ** ** **************. ***-*** is ******** *** ******** *******. *** is *****. ******** *** ** ********* worse. **'* *** **** **'* *** recommended, **'* ** ******** ******** ****.

(4)
(9)
UM
Undisclosed Manufacturer #2
Feb 10, 2022

**** ****-**** ** *** ******* **** Active ********* *********** **** ***** ** used ** * ****** ******?

UI
Undisclosed Integrator #3
Feb 10, 2022

*** ****** ******* *** ******** *****-*** to ***-**** ******* **** ********* ** cameras ** ********* **** ******* ***** up *** ********** ** * *******, or ************ ** ******** ****** *******?

******* *** **** ** ******* *****-** protocol **** ** ******* ******** ** code ** ********** ****** *** *** or ********?

CH
Conor Healy
Feb 10, 2022
IPVMU Certified

***** *** ***************** ** ******* ***** ***** ***.**** **** ****** ** ******* *** found ********* *********** ** ******* ** China.

(2)
JH
John Honovich
Feb 11, 2022
IPVM

*** ******** **** ** ** ** that ********* ****** ** **** **,*** R&D ********* ***** ****** **** ********** loudly *** ***** ***** *********** **** to ***** *** *** ** ** still ** ****-**** *** **** ********* this ** *** ***. **** **** this *** ***** *********'* ******* ** execute?

(6)
(1)
(1)
U
Undisclosed #4
Feb 11, 2022

"***** *****..... **. *****. *****."

(******)

"***** ******** ********* ******... *****. *****."

JH
John Honovich
Feb 11, 2022
IPVM

***** ***** ***** ***** ** ********* but *** ****** ******* ** *************** of **** ** **** ****.

*** *******,**'* ****** ** ********** ** **** *** ******* ** works ** *********:

IPVM Image

*** *** **** ****** ******* *** **** ************ ****** * ***** *** (****** the **** ***):

IPVM Image

*** ******** ********* *******:

IPVM Image

** ****** ******** ** ********* ** his ******** ***** *** ** ***** there ** **** ******** ** ***** at *********, **** * ******* **** of ******* ***************:

IPVM Image

***** ***** ** ***** ******* ** Hikvision, *.*., * *** ****** ***, Davis *** *********'* ************ **** *** ***:

IPVM Image

(1)
UI
Undisclosed Integrator #3
Feb 11, 2022

** ** *** ********** ******* ******* and ***********. **** **** * ***** market *****, *** *** ***** *****, why ** ****.

(2)
UI
Undisclosed Integrator #6
Feb 14, 2022

****, **** ** *** **** ** change *** ****-****. ** *** *** of *** ***, ******** ********** **** HikVision ** *******. *** ***** *** of *** ***** ** ****** ****-**** when **** ********** **** *** ** 2020. * ***** **** *** ***** to **** *** *** ** **** can ******* *** **** ***** **** the ****-****, *** ** ******'* ******** me ** **** *** ******* ** a *** *** ********.

JH
John Honovich
Feb 14, 2022
IPVM

* ***'* ****. ** **** ****** don't **** ****-**** ** ******* ** China, ** ****** ** ****** ******, from ** *********** **********, ** ** so. * ** ********* *******, **** is *** **** ************* *********** **** to ****** **** **** ***** ** be **** **** ** *** **** anyway.

UM
Undisclosed Manufacturer #5
Feb 11, 2022

********* ********* **** *** ****-****** ******** packages ** ********** **** *** ****** software *** ******** *** *********** ** a “****** *****” *** *********** ************ controls ** ******* *** ********* *** mitigate *** ******** ***** ***************. ***’* vulnerability ********** ***** ********* **** **** of *** *************** ******* ** *** outdated ******** **** ******* ** *** devices ******* ********** *********’* ********* *** contradicting *** *********** **** ******* ********* in *** *****-***** *** **** *********.

* ***'* **** *** ****** ** respond ** ****. * ** **** that *** *** *********** * ****** shell **** ********* *** ********* ********* with *** ********** ****-****** ********. ********* their ****** ***** ***'* **** ****** and **********.

(1)
Avatar
Carlo Kuijer
Feb 20, 2022

IPVM Image

CH
Conor Healy
Feb 21, 2022
IPVMU Certified

******:Hikvision ******* ****-**** ******* ********** ** *****

********* *** **** **** ******* *** iVMS-4200 ******** ******* *********** ** ***** in ** ****** ******** *** *, 2021 ****** ********** *** *** ****** on *** **, ****.

*** *** ******, ***** ********* ********** submitted, **** ** *** ******** **** "corrections **** ** ******** ** * future ****** ** ****-****." ** ***** Hikvision *** ******* * ***** ***** to *** *********** ** **** ******, and **** *** *** ******* **** any ************** ** *******:

IPVM Image

(1)