NVR Cybersecurity Rankings 2024 - Axis, Dahua, Digital Watchdog, Geovision, Hanwha, Hikvision, Speco, Uniview, Vivotek

bm
bashis mcw
Published Feb 08, 2024 15:00 PM

IPVM has released a ranking of 9 manufacturers' NVR's cybersecurity across 9 categories and 50 criteria. Watch the video below for an overview.

IPVM bought and tested NVRs from nine manufacturers for this ranking, evaluating Axis, Dahua, Digital Watchdog, Geovision, Hanwha, Hikvision, Speco, Uniview, and Vivotek based on the criteria explained in the Cybersecurity Rankings Criteria for IP Cameras, and NVRs Explained.

This report describes the strongest and weakest in nine main categories using 50 criteria.

  • Fundamental Built-In Security Features
  • Advanced Built-In Security Features
  • Attack Surface - WebUI
  • Attack Surface - HTTPS / TLS / SSL
  • Attack Surface - Disabled Services
  • Digital Fingerprinting
  • Cloud / P2P Connection
  • Firmware Updates
  • Manufacturer Cybersecurity Support

This is a cybersecurity companion to our report NVR Rankings 2023 - Axis, Dahua, DW, Geovision, Hanwha, Hikvision, Speco (TVT), Uniview, Vivotek.

Our results are presented in five groups: strong, above average, average, below average, and weak.

Where the research section details each category and an overall ranking based on test results, with a redacted version below:

IPVM Image

Executive *******

**** ***** *********** ***********, ******** ***** below.

IPVM Image

Differentiators ********

***** *** **********, *** ******* ************** between *** ********* *** ******* ********** was *****/*** **********.

***** *** ************* ***** *****/*** ********, Dahua, ******, *****, *** ******* **** enabled ** *******, ***** ****** **** disabled ** *******. *** *********** ********** was *** *****/*** ******** ******, ***** varied **** **** ******** ** ***********, with *** ******* **********.

**** ****** *** *************' *****/*** ********, and ** **** ** ****** * separate ****** ********* *** ******** *** each *****/*** *******.

**** *** ******* ******** ***** *** strongest ******* *****/***/*** ************, **** ***** and *** **.* ******* ** ******* and ** ******** *******. *****, *****, and ******* *** *** ***** ** default, **** *****, *********, *********, *** Uniview ***** *** *.*. ************* ***** TLS **.* *** **.* **** ****** equally ** *** ******* ******* **** are **** ******* ******** ** ***. However, ** ****** ** ***** ***** versions *** ** *** ** **.* was ******** *** ***** ***** **.* and *** ******** *** *********** ************.

*** **** ****** ******** *** ******** ciphers, *** **** ******* ****** ** resources ******* **************.

****** *******, ******* **** ******** ********** TLS **.*/**.*, ** **** ** ******** ciphers.

*********** *****-** ******** **** ****** ****** variable *******, **** *** ****** ********** not ******** ***, ****** ****, *** Signed ********. *******, *** ********-********** **** did *** *** *****-***** ***** *******.

************ ************* *** ********* **** *******, with **** **** ******* ******** ** all ***** **********. ******** **** ** Materials (****) *** **** **** ******* (LTS) ******** *** *********** ******* ******** for **** *************.

Test ***********

*** ******* ******* ********* *** **** was ******** *** ******** ** *** current *******, ********* *** *** ** factory ********, *** ******* ** **** services *** ******** *** ******* ** default *** **** ** ********* ** be ******* ****** ****** **********.

********, **** ** ***** *** *****/***, were ***** ******** ******* ****** *** test ** ****** ********** ******* ******* manufacturers.

**** ***** *** ** *** ****** NVRs ** ** ***:

  • ******* ********: ***** *&* **., ***
  • ***** ************: ******** *** ******* ********** Co., ***.

***** ** *** **** *******, **** asked *** ******** **** *** *************, with *** *** ***** **********, **** with ******* *********. ** ***** ********, we **** ****** *** ****** **** their ******** *** *** * *******.

******* **** **** **** **** ** release ******* ******** ** **/****, *** both ******* *** ****** **** ****** updated ******** ** *******.

Strongest *******

**** ******* *** **** ******* ***** on *************, **** ****** ******* ** 3 *** ** * **********. **** was *** **** ************ **** *** strongest ******* ** *** * ************ Cybersecurity ******* ********. *******, **** **** many ****** ********* ********* *** ***-************* HTTP ******** **** ****** ******* ****** information ** * ********* ********.

IPVM Image

Above ******* **********

****** *** **** ******* ** ****** Surface - *****/***/*** *** ******* **************, average ******* ** * *** ** 9 **********, ******* *** ******* *** secure ****.

IPVM Image

********* *** ****** ******* ** *****/*** Connection, ******* ******* ** * *** of * **********, ******* *** *** TLS **.* *******, ******** ** *** brute ***** ***** ******* *** ***** enabled ** *******.

IPVM Image

****, ***:

Average **********

***** *** **** ******* ** *********** Built-In ******** ********, ******* ******* ** 4 *** ** * **********, ******* TPM *** *** **.* *******, ******** it *** ***** ***** ***** *******.

IPVM Image

******* ** *** ********* ** *** manufacturers ** ******** *****-** ******** ********, with ***** *****'* *** ******** ******** directly ********** **** *** ***. *******, Vivotek ** ******* *** *******, ****** boot, *** ****** ********. *** *** not ********* ***** ****-****** ******** ** the ***.

*** **** **** ************* ***** ***** ***** ******** ****** App ******.

IPVM Image

Below ******* **********

******* ******** *** **** ******* ** Attack ******* - *****/***/*** *** ******* Fingerprinting, ******* ******* ** * *** of * **********, **** *********** *** advanced ******** ********, ******* *** *******, secure **** *** ****** ********, *** not ********** ***** ****-****** ******** ** the ***.

IPVM Image

***** *** **** ******* ** ****** Surface - ******** ********, ******* ******* in * *** ** * **********, missing *** *******, ****** ****, *** signed ********, *** *** *** ******** their ****-****** ******** ** *** ***.

IPVM Image

******* *** ****** ******* ** ******** Update, ******* ******* ** * *** of * **********, ******* *** ******* and ****** ****, *** **** ******* in ******** *****-** ******** ******** *** Cloud/P2P **********.

IPVM Image

Weak *********

********* *** ******* ******* ** * out ** * ********** *** ** one ** *** *** ************* **** distributed *********** ********, ******* *** *******, secure ****, *** ****** ******** **** weak ******* ** ***** *** ******** security ********.

********* **** ******** ** ***** ***** Authentication *** *** ** *** ****.

IPVM Image

Summary *****

***** ** *** ********** ***** ******* tested *******, *** *****, ** **** provide ******** *********** ** **** **** (click ** *******).

IPVM Image

Fundamental *****-** ******** ********

*********** *****-** ******** ******* *********** *** based ** ********* *** ******** **** ensure ****** ****** ****** *** *** prevent ********** ******* **** ******** ******.

IPVM Image

***** ****** **** *** **** ********* by ****, *****, *** *********, ****** firmware *** **** ******, *** **** was *** **** ************ ** ******* a ******* ******** ******.

** ******* ********* *** * ****** feature ***** **** *** *** ******* from ******* ******** *** *********. ** address ******* *** ***** ************** *** are ****** *** ********* ***** ***** of *******.

IPVM Image

***** ******* ** * ****** *** effective ****** ** **** **** ** prevent * *****-***** ****** ** ******* out *** * ****** **** ***** a *** ********* ***** ********.

IPVM Image

Advanced *****-** ******** ********

******** *****-** ******** ******** *********** ** based ** ************* ********** ** ******* devices **** *******.

IPVM Image

****, *****, ******, *** ********* ******* the **** ****** **** ***.** ***-***, and ***** ******** **** ***-***, ***** is ***** ** ******** ******* *** is **** ****** **** ***.

IPVM Image

******* ** *** ********* ** *** manufacturers ** ******** *****-** ******** ******** with ***** *****'* *** ******** ******** directly **** ***** ****:

IPVM Image

Attack ******* - *** **

***** ************* ******* *********** *** ***** on *** **** ***** ********* *** information ********* ****** *** ************** *** authorization.

IPVM Image

*** ************* ******* *********/******** **********, ****** Geovision, ***** **** ******** ***** **************, which ** ****** ******** *** **** easy ** ******.

IPVM Image

IPVM Image

***** **** ************* ****** *** *** UI ****** **************, ** ***** ** testing **** *********** *** ** ************** solutions *** **** ********** *** ******** functionality, ***** ** * ********* **** of ******.

** ******* ** * ********** *********** WebUI ************** ******** ** ******** ************** ****** **** **** ******** on ** ****.

***-************* ******** ******

********* ********* *** *** *** ********* is ***** ******** ** *** ***** path *** ******** **** *** *****.

****** *** *** **** ************ **** strictly ******** ********** ***** ****** ** could ****** ******** **** *** *** interface.

IPVM Image

** ********, ********* ****** ****** *** pre-authenticated ***** ****** *********.

IPVM Image

******* **** ********

****** *******, ** ********** **** ********* has * ******* **** ******* **** a ******* ********, ***** ****** ** used ** *** **** *** *** interface.

IPVM Image

******* *******

*****, ******* ********, *** ********* **** the **** ************* ** *********** ******* timeouts ****** *******.

IPVM Image

Attack ******* - *****/***/***

*** *********** ** *****/***/*** ******** *** based ** ******* ***** ** ******* and ******** ** *******, ***** *** protocols *** ***** ****, ***** ******* are ***** ****, *** **** ************* issues *** *****.

IPVM Image

****, ******* ********, *********, ******, *********, and ******* **** ***** ******* ** default *** ** *** ******* ******** protocols **** ** *** **.* *** v1.1.

**** ** ******* ***** ** *****, Speco, *** *******, ** ***** **** Uniview ******** ******** *** **.*/**.* *** ciphers. ******** ******* **** **** ****** among *** **** ******.

*******, ***** ****** ** ***** ********** even ****** *** ********** *** **** HTTP, ***** ***** *************' **** ****'*.

IPVM Image

Attack ******* - ******** ********

*** ******** ******** ******* ** ***** on *** **** ********, ***** *** be ******, *** ******* ** *******, increasing *** ****** *******.

IPVM Image

**** ** ******* ** ******* ** all *** ************* ******* **** ** the ******** **** ** ****** ***** in **** *******.

***** *** ******* **** **** ***** to **** ***** ******* ** *******, and ***** ** ** ****** ** have **** *** ***** ******* ** default. ***** ***** ******** *** ** disabled, ** ** **** ****** **** they **** *** **.

**** ******* *** ******* ***, ** found ******* **** ***** **** ************** services ** *** ***** **, ****, 6060, *** ****.

****** *** ************* *** ****** ************** with ****, ****** ******* ******** *** Geovision, ***** *** ***** **************.

IPVM Image

******** *** ******* *** ********* *** keeping *** ******* **** ** ** cameras, ** ** ** *********** ******* to **** **** ** ********. ** should ** ******* ** ***** *** use *** *******.

IPVM Image

Digital **************

******* *********** *********** *** ***** ** the ********** **** ***** *********** ********** about *** ******, **** ** ** address, *****, ******** *******, ***.

IPVM Image

** ***** **** ******* *** **** Discovery ******** ** *** ********* ** disabled ** **** *************, ****** ****, which *** ** ******* ** *******.

******** **-*********, ****/****, *** *********** ********* protocols **** ****** ***** ****** ****. However, ****/**** ** **** *** ********* purposes *** *** *** *** *********.

************, *** ***** *** *********, ** recommend ******* *** ******* ** ****** ***** *** ********* Devices ****** ************ **** ******** ** ** ******** 2022.

*** ********* ******** ** ******** *** local ***. **** **, ** *********** sends * ******* ** * ********* address (*.*., ***.***.***.***) ** ********* ******* (e.g., ***.***.***.***), ***** *** ********* **** be ******** ** *** ******. *******, this **** ** ******* *** **** be ******** ** ******** ** ********* by ****** ********* *** *********/********* ******* with *** ******** ** *******. **** means *** *** ****** *** ****** outside *** ***** *******, *** *********** can ** ********* ********.

***** *** ***** ******** ** *** information ********* ******* ***** ************** **** provide **** *********** ***** *** *******.

****

** ********** *** ************, *****, *** Firmware ******* *** **** ********:

IPVM Image

Digital ********

***** ** **** ****, ** ********** that *** ******* ******** *** ** a ***** *** *******.

IPVM Image

*****

** ********** *** *****, ******** ** address, *** ******** ******* *** *********** discovery ******** *** ********:

IPVM Image

******

************, ** ********** *** *** ***** using ****** *******.

IPVM Image

Cloud/P2P **********

***** *** *** ********** *********** *** based ** *********** ** ******** **********, encrypted ** ***-********* *************, ***** ***** leave ******* ********** ** *******.

IPVM Image

*** ************* ***** *****/*** ********, ***** Dahua, ******, *****, *** ******* **** enabled ** *******, ***** ****** **** disabled ** *******.

******** ***** ******** ******* ****, ****, Hikvision, ******, *** ******* **** **** found ** ******* ***** *****/*** *******.

*****, ******* ********, *********, *****, *** Uniview *** *** ******* ***** *****/*** traffic, ***** ** **** ***** * mix ** ******** *** *********** *********.

**** ****** *** *************' *****/*** ********, and ** **** ** ****** * separate ****** ********* *** ******** *** each *****/*** *******.

Firmware ******

******** ****** ******* *********** *** ***** on *** ************ ** ***-********* ******** for ************ *** **** ** ******** updates.

IPVM Image

*** ************* ***** ***** ******** ********, with ******* **** ** ******* *** right ***** *** *******. **** *** the ******* ** **** *** ***** model *** ********* ******** ** ***** website.

****, *********, *** ******* ******** **** not ********* *** ***********, ***** *** other *************' ******** *** *********.

***** **** ******* ** *** **** and ***** *****-** ********, ** ****'* consider ********* ******** ******* ** ******** for ******** *******.

** ******** *** ******* ******** ** the ************'* ******* *** **** *****-** functionality, ***** ** **** ***** **** Cloud/P2P **** ** ******* ** *** cloud ******** *******.

************, *** ******** *** ******* ******* Cloud/P2P **** ** ******* *** *** built-in ******* ** ****, ****** ** some *********** *****.

**** ** ***** ** ******* ***** Cloud/P2P, *** *** ****** **** *** online ******* ***** *** **** ** disabled.

IPVM Image

**** *** ******* *****/*** ** ********, the *** ******* **** * *** version *** *** **** ***** ** an ***** *** ********.

IPVM Image

********* *****/*** ** ******** ** *******, and *** *** ******* *** ******* version ** *** ******, ******* ** error ******* *** ******* ********* *** a ***** *******.

IPVM Image

Manufacturer ************* *******

************ ************* ******* *********** *** ***** on *** ************'* ******* ************* ******* and *****, ********* ******** *** ******** transparency *** ****-**** ******** *******.

IPVM Image

***** *** ************* ******* ***** ******** guides *** ******** ******** ***** ****-****** licenses, ******* ********, *****, *** ******* stood *** ** *** ********** ***** open-source ********.

*******, ******* ******** **** **** **** the****-****** ******* ********** ***** ** ***** on ***** *******.

**** *** ****** ******* ** *** seven **********, *** **** ************ **** provides * ******** **** ** ********* and * *** ****** *******. ****, Digital ********, ******, *** ******* ***** LTS ********.

***** *** ************* ******* ************* ********, Speco ***** *** ** *** ********* one, *** * ****** ** ******'* website ******* **** **** ****, *** of ***** **** ******* ** *** Hardening ***** *** *** ************* ******** Policy.

IPVM Image

*************** *******

******* *** * ****** ******** ******* service, ********** ** ******* ***** ********** ******* ****** ****** **** * customer ***** **********. *** ******* ** disabled ** ******* **** *********** ******* and ****** *********** *************.

IPVM Image

*** ********

****, *****, *********, *** ******* ***** administrators ** ****** *** ******* ***** WebGUI, **** **** *** ********* * shell **** ***** ********** ******* ** root **********. ***** *****, *********, *** Uniview **** ***** ********** ********* ******.

******** *** ******* ** ********** ** devices, **** **** ***** ** ** enabled ** *******, ***** ** **** cyber *******.

IPVM Image

**** *** ***** **** **** ****** default **** ****** **** *** ** enabled *** ******* ******** * ****** SSH **** ** ** ******* **** lower **********, ** **** *****.

IPVM Image

******** **** ****** ** **** ******* is ***** ******** *** ******** ********** configuration.

** ********, * ********* ***** *** a ********** *** ******* ******* ***, as **** ***** ** *****'* ********* shell.

IPVM Image

****** *** ************* ** *** ******* NVR, **** ********** ******* ******* ******** that ******* **** ******** ** *** shell, ***** ** *** ********* ** the ******. ** ********, ** **** found **** ** *** ******** ** activate * ****** ******.

IPVM Image

*******, ******* **** **** **** *** SSH ***** ******** * **** *******, and *** ************* ******** **** ** generated ******* * ******* ******** ****.

IPVM Image

** ********, ******* **** **** **** that *** ****** ****** **** ** removed ** *** **** ******** ******** version.

IPVM Image

*** ********* *************' **** *** ******** versions **** ******.

Comments