HomeSecurityAxis Communications: Vulnerability exposes credentials for Azure Storage Account

Axis Communications: Vulnerability exposes Azure Storage Account credentials

A critical vulnerability in Axis Communications' plugin for Autodesk Revit has exposed Azure Storage Account credentials, creating significant security risks for customers and enabling supply chain attacks targeting the architecture and engineering industries.

Axis Communications Azure Storage Account

The vulnerability stems from hardcoded credentials embedded in signed Dynamic Link Libraries (DLLs) distributed to clients via the plugin’s Microsoft Installer (MSI) package . The security issue was discovered in July 2024, when Trend Micro’s VirusTotal rules detected Azure Shared Access Signature (SAS) tokens inside a digitally signed DLL named “ AzureBlobRestAPI.dll ”.

The affected component was issued to AEC Advanced Engineering Computation Aktiebolag, an Autodesk partner specializing in AutoCAD and Revit consulting. This discovery initiated a remediation process that lasted months and included multiple vulnerability reports and patches.

See also: PoC Exploit for Lenovo code execution vulnerability

The exposed credentials provided unauthorized read and write access to three Azure storage accounts belonging to Axis Communications, a Swedish multinational company specializing in network video solutions and surveillance technology. These accounts contained critical assets, including MSI installers for the Axis Plugin for Autodesk Revit and Revit Family Architecture (RFA) files used by customers for building information modeling projects.

The impact of the vulnerability was amplified by the ability of attackers to replace legitimate files with malicious versions, essentially exploiting the trusted distribution mechanism.

Trend Micro analysts have identified issues beyond credential disclosure. Through their Zero Day Initiative (ZDI) research, they discovered multiple remote code execution in Autodesk Revit that could be triggered by importing malicious RFA files.

Axis Communications: Vulnerability exposes Azure Storage Account credentials

This combination of vulnerabilities created a dangerous attack vector where malicious actors could potentially compromise storage accounts, upload crafted RFA files, and achieve a mass breach of Axis Communications customers using Autodesk Revit software. The discovery highlights broader supply chain security risks within the architecture and engineering software ecosystem.

See also: Happy DOM Vulnerability: 2.7 Million Users at Risk

The plugin's design flaws show how trusted third-party integrations can become attack vectors when proper security controls are not implemented.

Axis Communications: Technical analysis of the attack

The technical basis of the vulnerability lies in poor credential management practices within the plugin architecture. The researchers found clear-text Azure SAS tokens and key pairs shared access for two Azure storage accounts named “axisfiles” and “axiscontentfiles” (encased inside a private method called “internalSetEnvironment” of the “AzureBlobRestAPI.DataTypes.Classes.Global” class). The credentials provided extensive privileges, including full read, write, delete, list, append, create, update, modify, and execute permissions on the accounts.

Axis Communications: Vulnerability exposes Azure Storage Account credentials

This level of access allows attackers to not only access existing content but also modify distribution mechanisms and upload malicious files. When Axis Communications initially attempted to fix the issue with version 25.3.710, it implemented code obfuscation using tools such as Eazfuscator. However, this approach proved to be inadequate as obfuscated credentials could be easily decrypted using publicly available tools such as de4dot. Obfuscation merely provided security through obscurity, rather than addressing the fundamental design flaw of embedding credentials in client-side code.

See also: Oracle E-Business Suite: New RCE vulnerability exposes data

Even after implementing read-only SAS tokens in version 25.3.711, the issue remained unresolved. Finally, Axis Communications confirmed that this vulnerability and others have been fully patched in the current version 25.3.718.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The company has also taken precautionary measures to notify affected partners and customers, emphasizing that the Autodesk Revit add-in is only provided to select partners and is generally not accessible for public use.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS