HomeSecurityHikvision DVRs have security holes that allow full control...

Hikvision DVRs have security holes that allow complete control of the device

Many Hikvision digital video recording products have been found to be vulnerable to security flaws,

Several Hikvision digital video recording products have been found to be vulnerable to security flaws, which could allow an attacker to gain complete control of the device.

This type of equipment is used for surveillance in commercial buildings and their surroundings and in some cases, even for surveillance of private properties. Owners of these devices have remote access and manage the devices through a web application which is also available for mobile devices.

Security researchers from Rapid7, after examining data from Project Sonar (a public network analysis community), identified three vulnerabilities (CVE-2014-4878, CVE-2014-4879 and CVE-2014-4880) in Hikvision's RTSP (Real Time Streaming Protocol) request handling code.

Researchers analyzed the DS-7200 series products and determined that they could be compromised by a malicious user who could exploit buffer-overflow vulnerabilities in the RTSP body, header and basic authentication handling. This protocol is intended for controlling streaming media servers between endpoints.

The technical details of these vulnerabilities were published by Rapid7's Mark Schloesser in a recent blog post.

According to the researchers, there are about 150,000 such IPv4 devices that can be remotely controlled. In some cases, the equipment is protected by the default pair of credentials (admin: 12345) set by the manufacturer.

Exploiting the RTSP basic authentication vulnerability does not require the attacker to log in, and a Metasploit module was published on Wednesday.

It appears that Hikvision has contacted security researchers about the issue, but no response has been provided so far. Until the issue is fixed, users should resort to additional security measures, such as accessing the devices via VPN. It goes without saying that users should change their default credentials (username and password) as soon as possible.

According to Rapid7's vulnerability disclosure timeline, Hikvision was notified of the issue on September 15, 2014. In early October, researchers reported the issue to the CERT Coordination Center (CERT/CC) and a few days later were assigned CVE (Common Vulnerabilities and Exposures) identifiers.

Rapid7 warns that researchers at the SANS Institute this year discovered a botnet made up largely of DVRs and routers and used for Bitcoin.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS