"BIG Payouts": SSD Seeks Critical Vulnerabilities for Axis, Dahua Devices

bm
Avatar
bashis mcw and Charles Rollet
Published Aug 17, 2023 14:01 PM

The company offering up to $75,000 for Uniview exploits is now seeking vulnerabilities for Dahua, Axis, Mobotix, and truVision (i.e., Interlogix OEM of Hikvision) devices.

IPVM Image

This is part of a broader campaign for SSD, the zero day broker who sells early access to cybersecurity vulnerabilities.

In this note, IPVM examines the company, SSD, and their latest payouts offered for vulnerabilities, including feedback from SSD, Axis, and Mobotix to IPVM.

SSD **********

*** ****** ************** ******** *********** ** ******* *************** for "* **** ***** ** ******** and ********." *** ************ ** ******************** *****, *****, *** ***** (*** SSD ****) *** ***** ** ****** conference ** *********** **********,**** *** ** *** ***** ** the **** ***** ************ *************** *******.

** **** ****,**** *********** ******** ** ** $**,*** *** Uniview ***************, ** ******** ******' *** ****** *************** ** ** $*,*** *******, *****, just **** *****,**** ******* ** $*,***.

"BIG *******" & "**** ******" *** ***** ************ ***************

*** ** *** ********* "*** *******" for ***** ***************, ** **** ** a**** ** ********* *****:

IPVM Image

*** ********* ****** ***"*****"(*.*., *** ************* ** ***** *************** for) ** **** ***** ***** ****'***** **** ******* ******:

IPVM Image

*** **** ********* ** ****** ** tweet***** *** "******* ** ****** *************** are *** ** **** ******!"

IPVM Image

*******, ******* ******************** ** ********* *******:

IPVM Image

********* ****** ** ********** ******** *********, ***** ** **** in ***'*"*****"****, *** **** *** ******* *** case **** ********* ***** ***** ***.

Pre-Auth ************* ********

*** ** ******* '***-**************' ****** ****/******* Executions *** *** *** ***** *******, per *** ************* *******,*****,*******, ************.

***-**** **** ******** ******* ***** *** username/password/login ****, ****** **** ********** ******** and **** ******** **** ****-**** ***************.

*** ******** ******** *** ******* ************* severity, ****,****** ******* **** ***** "** ******** [*.*. most ******] ** ** ********** *** required".

Axis, ******* ** *** **** **** ***

**** **** **** ** *** "*** received *** ************* *******" **** *** and "**** *** **** **** *** specific ************":

IPVM Image

**** ******* ** ***, ** *** we **** *** ******** *** ************* reports **** **** ** *** ******** available ******* ***********-********@****.******** ******* *** ****** ******* **** we ********** **** *** **** ** Bugcrowd.

**** **** *** **** **** *** specific ************ *** ******** *** ******** researchers, ******* ******* *** ************* ** submit ********** *************** ** **** ** they *** ********** ** **** ** can **** **** ****** ******* *** joint *********** ********** *******.

******* **** **** ** "**** *** have *** ************ **** **** ************ but ****** *** ********".

***** *** ********* *** *** ******* to ******* ********, ** **** **, we **** ******.

Risks ********

*** **** **** ** ***** ***** access ** *** *************** ** **** to *** *********, ******* ******* *** cybersecurity ********.

*** **** ** ****, *** *** companion ******:**** *** ****** ***** ***** ****** To ************* ***************.

Comments (4)
Avatar
Ross Vander Klok
Aug 17, 2023
IPVMU Certified

*** **** ******** **** **** *** Uniview ******* * ****** ** ******** them **** ** **** **? * don't ********** *** ******** ***** * guess ******* **** ***** **** ** awful *** ** *** ** **** are ***** ** *** ** *** lawful *** ******* ********.

bm
bashis mcw
Aug 19, 2023

*** ******* **** ** "** **", for **** **** **** ***** ****** $75k

RS
Robert Shih
Aug 19, 2023
Independent

****** *** ** ***** ** **** at **** ****. *** **** ******* has ** ****** **** **** *******?

bm
bashis mcw
Aug 19, 2023

****, * ***'* ***** **** *** serious *** ******* ******.

* ***** ** * **** ****** by **** **** ** * ****'* care ***** ******.

**** ***** *** *'* ******, ***** I **, *** * ***'* ****.