Qognify NiceVision Hardcoded Credentials, 10.0 Critical Vulnerability

Published Oct 10, 2023 15:15 PM

The US Government issued an advisory this month for Qognify NiceVision Net 3.1 using hard-coded credentials.

IPVM Image

In this report, IPVM analyzes the vulnerability advisory, what it impacts, CVSS scoring, and more.

Executive *******

******** ******** *** *** *.* *** older, ******* **** *** *** ******* would ******* ******* *** ******* *.* was ********. ******* *** *** ****** Hexagon *** *** ******* ******* *** have *** ****** * ****** ** their ********. ** ** * ******** sign *** *******'* ************* *****, ** hard-coded *********** **** **** ******** ********** as ** ******* ******** ****, ***** should **** **** ***** ** ******** software *******.

*** ************* ***** * **** ****, per *** ********, ** ** ****** attackers ** "******** *********** ***** *** cameras, **** ***********, *** ****** ******** records." ** ******** ***** **** ******** control ** *** *** ** ****** the ********, ********* ** *******.

**** ******** ** ******** ***** **** access ** *** ***** ******* ***** the ****** ** *********. *******, ** method ** ***** ** ******* *** disclosed *** **** ** ******. **.* scores *** ********, *** *** ****** information ** ****** ** ******* *** it ************ ******** **** *****. ** plan ** ****** **** ****** ** more ******* *** ********.

********* ** *** **** ********, ******* released ****** **.* *** *** ** patch *** *************. *******, ** **** states **** ***** **** ** ****** software *********** ********* **** *******, ******* they *** *********** ******** *** ****** this ******** *************. *******, ******* **** provided * ******* ********* ***** ******** to *** ****** ******** *******.

No ******** **** ******* ** *******

******* *** ********* *******, ******* (**** ******), *** *** ******* ** ******** attempts *** ******* **** **** ****. IPVM **** ****** *** ****** ** either ********.

UPDATE - ******* ******** ******** ** *******

******* ********* ** *** ******* *** a *********:

** ********* ********* ** ****** ** the ****** ******** *******. *** ********* that *** ** ******* ** ***** version, ******** ** *** ******* ******* provides ********** ***** (********** *.* *** with *** *******).

**** **** *** ******* ******** ****** or ******** ******* ** ****** ** avoid **** **** ** ***** ** the ******. ****, **** ** *** address ******* *** ************* *** ******* in ***** ******** ** *.*, *** 3.1 ******** **** ***** *******, ** 3.2 *** ********, *** *** ********** only ****** *.*.

Qognify / ******* ************* ****** ** ********

*******'* **** ** ******** *** ** public ******* ***** * **** ** transparency **** *** ******* *** ****** questions ***** *** ********** ** *** cybersecurity. ***** **** ******** ******** ********* have ******** ***************, ***** **** ******* to *** *************** **** ************ *********** a *********** **** ************ **** ** be ****.

Hard-Coded *********** *********** ****

****-***** *********** *** * *********** ******** risk ******* **** *** **** ** exploit *** ****** * ****** ***** of ************* *******. **** ** * well-known *** ********** *******, ** ********** banned ****-***** *********** *** ******* *********.

******* ************ *** ******* **** **** ** credentials *** ****-*****, ****** *** ******* indicates **** ** ** *** ******** credentials:

******* ********** ******** *.* *** ***** are ********** ** ******** ********* *********** using ****-***** ***********. **** ***** *********** an ******** *** ******** *********** ***** the *******, **** ***********, ***modify ******** *******. [emphasis added]

*******, **** ****** ******* **** ** the ******** *********** ** ************.

NiceVision ******* *.* / *.* ****** *******

***** *** ******** ****** *** ************* is *** ******* *.* *** *****, it ** ******** **** *** ********** could **** **** *.* ******* ******* software ** *** ******** ********* *** the ************* **** ******* ** ***** versions ** *.*. *******, ** ** also ******** **** ******* ***** *** issue ** ** ******* ******* ** 3.2, *** *** *** ***** * patch/update ** *** *** ******* ** previous ********.

** ******* ******** **** ******** *********** about *** ******** ********, **** **** update *** ******.

NIST ******** ***** *** ******** ***

***** **** ******** * **.* *****, NIST/NVD ****** ******** ** ******** ***** ***:

IPVM Image

**** *************** *** ******* *** **** scores ********** ******* ** ****** ******** or ****-******. ** ********, ******, ********** those **** **** ******** *********** ** lower ********* ********, *** **** ****** to ******. *** ****** ********** **** can **** **** ******* **** ** several *****.

**** **** ********* * **** ***** of **.*, *** ****** ******* **** relatively *******, *** **** *** **** detailed *********** ** ***** ********, ** may **** ******. *** *** ** marked ** ********* "********** ********":

IPVM Image

10.0 ************* ******* ********

*******, **.* ************* ******* *** ********; for *******, *********'*"******* ***** ** ******** *************"********'* ******** ***************** *.* ** ****. *******, ****'* scoring **** *** ******* *** *** 10.0 ****** *** *****.

*** ******* ***************, **** ***** ****** a ****/*** ***** ******* *.* *** 9.8, ****** *** **** ** *********** makes ** ********* ** ******** **** specifically.

NiceVision ****** ******* ****** *** ****** *********

******** ** *** *** ******, *** NiceVision *** ****** ******* * ********* version ******* ****** **** *** ********** Net ****** ********.

****, ********** *** ********'* ****** ******* is ******* *.*. **** ***** ******* users ******* * ****** ******* ** the ********** *** ****** *** ** not ******* **** **** ** ****** the ****** ******** ** *** *** issue.

OTORIO ********* ******* ********

************* ****, **************** *** *************. ** *** ******** veteran **** **** ** ***** ** experience ** ************** *** *************, **-******* the *******. ******** ***** ** *********, 80% ** ****** *** **% ** the **.

**** ***** *** **** ******* ** other ******** ******** ************* *********** ** Otorio, ****** **** ** *** ******** and ********* ** ******* ** **********/************* devices *** ********** ******* *******.

Comments (5)
Avatar
Brandon Knutson
Oct 10, 2023
IPVMU Certified

*** ************* ** **** **** *******'* NiceVision ******* *** **** *******'* ******* shows "******* ***" ***.

(1)
UI
Undisclosed Integrator #1
Oct 10, 2023

*******, ** **** ****** **** ***** need ** ****** ******** *********** ********* with *******, ******* **** *** *********** charging *** ****** **** ******** *************.

** **** ****** **** ***** ***** that ******* ****** *** *****?

Avatar
Sean Patton
Oct 12, 2023

**** ***** **** *** ***** **** provide *******/******** *** ******** *************** ***** the ******** ** ***** *********. **** a ******** ******* ** ********** *** of ****, ** *** ** *******, then ***, * **** ***** **** to *** ** *** ** * newer ******* *** *** *** *****.

*** ***** ******** ******** **** *** typically ******* *** ******* ******* *** may ******* ******* ***-******** *** *****.

******* *** ******* **** *** ****** that *.* ** *** ** *******, but ** ** ****, ** ***** unlikely **** **** ***** *** **** made **** ***** ** ****, ***** ***** ******** *******.

Avatar
Sean Patton
Oct 12, 2023

*******'* ****** *******, ******* ********* *** the ****** *** **** ******* ** reflect.

UPDATE - ******* ******** ******** ** *******

******* ********* ** *** ******* *** a *********:

** ********* ********* ** ****** ** the ****** ******** *******. *** ********* that *** ** ******* ** ***** version, ******** ** *** ******* ******* provides ********** ***** (********** *.* *** with *** *******).

**** **** *** ******* ******** ****** or ******** ******* ** ****** ** avoid **** **** ** ***** ** the ******. ****, **** ** *** address ******* *** ************* *** ******* in ***** ******** ** *.*, *** 3.1 ******** **** ***** *******, ** 3.2 *** ********, *** *** ********** only ****** *.*.

(1)
jh
justin holstein
Nov 01, 2023

****, ********** *** ********'* ****** ******* is ******* *.*. **** ***** ******* users ******* * ****** ******* ** the ********** *** ****** *** ** not ******* **** **** ** ****** the ****** ******** ** *** *** issue.

*.* ** *** ****** ******** ******* for******* ***,*** ********** - ***** ** ******* Qognify *** ******* 😵.