Main menu

Pages

Dahua IP Camera Vulnerability Could Allow Attackers to Take Full Control of Devices

Details have been shared about a security vulnerability in Dahua’s ONVIF (Open Network Video Interface Forum) standard implementation, which, when exploited, can lead to IP cameras being taken over.

Tracked as CVE-2022-30563 (CVSS score: 7.4), the “vulnerability could be exploited by attackers to compromise network cameras by sniffing a previous unencrypted ONVIF interaction and replaying the credentials in a new request towards the camera,” Nozomi Networks said in a report Thursday.

The issue, which was resolved in a hotfix released on June 28, 2022, affects the following products:

  • Dahua ASI7XXX: Versions prior to v1.000.0000009.0.R.220620
  • Dahua IPC-HDBW2XXX: Versions prior to v2.820.0000000.48.R.220614
  • Dahua IPC-HX2XXX: Versions prior to v2.820.0000000.48.R.220614

ONVIF governs the development and use of an open standard for how IP-based physical security products, such as CCTV cameras and access control systems, can communicate with each other in a vendor-neutral manner. .

cyber security

The bug identified by Nozomi Networks lies in the so-called “WS-UsernameToken” authentication mechanism implemented in some IP cameras developed by Chinese firm Dahua, allowing attackers to compromise the cameras by replaying user information. identification.

In other words, successful exploitation of the flaw could allow an adversary to secretly add a malicious administrator account and exploit it to gain unrestricted access to an affected device with the highest privileges, including watching live camera feeds.

All a malicious actor needs to mount this attack is to be able to capture an unencrypted ONVIF request authenticated with the WS-UsernameToken scheme, which is then used to send a forged request with the same authentication data to trick the device create the administrator account. .

Dahua IP Camera Vulnerability

This disclosure follows the discovery of similar flaws in Reolink, ThroughTek, Annke and Axis devices, highlighting the potential risks posed by IoT security camera systems given their deployment in critical infrastructure.

“Threat actors, particularly nation-state threat groups, may be interested in hacking IP cameras to help gather information about the target company’s equipment or production processes,” they said. said the researchers.

“This information could facilitate reconnaissance performed before a cyberattack is launched. With better knowledge of the target environment, threat actors could design customized attacks that could physically disrupt production processes in critical infrastructure.”

cyber security

In a related development, NCC Group researchers have documented 11 vulnerabilities affecting Nuki smart lock products that could be weaponized to obtain arbitrary code execution and open doors or cause a denial of service (DoS) condition.

Also of note is an Industrial Control System (ICS) advisory issued this week by the US Cybersecurity and Infrastructure Security Agency, warning of two serious security vulnerabilities in MOXA NPort 5110 servers running firmware version 2.10.

“Successful exploitation of these vulnerabilities could allow an attacker to alter memory values ​​and/or render the device unresponsive,” the agency said.