Hikvision Patches Security Flaw in Network Cameras, Preventing Cleartext Credential Transmission
Hikvision, a leading provider of network cameras and surveillance systems, has released firmware updates to address a security vulnerability that could expose users’ Dynamic DNS credentials. The vulnerability affects a wide range of Hikvision network camera models and could allow attackers to intercept sensitive information or disrupt communication between the camera and the Dynamic DNS service.
The Vulnerability:
Older firmware versions of Hikvision network cameras only supported HTTP communication with Dynamic DNS providers like DynDNS and NO-IP. This meant that usernames and passwords used to access these services were transmitted in cleartext, making them susceptible to interception by attackers.
Impact:
An attacker exploiting this vulnerability could:
- Steal Dynamic DNS Credentials: Capture usernames and passwords, potentially gaining unauthorized access to the user’s Dynamic DNS account.
- Disrupt Communication: Interfere with the camera’s connection to the Dynamic DNS service, preventing remote access to the camera.
- Launch Further Attacks: Use the compromised Dynamic DNS account to redirect traffic or launch other malicious activities.
Affected Products:
A wide range of Hikvision network camera models are affected, including:
- DS-2CD1xxxG0, DS-2CD2xx1G0, DS-2CD3xx1G0, IPC-xxxxH (versions prior to V5.7.23 build241008)
- DS-2CD29xxG0 (versions prior to V5.7.21 build240814)
- DS-2CD1xxxG2, DS-2CD3xx1G2, HWI-xxxxHA, IPC-xxxxHA (versions prior to V5.8.4 build240613)
- DS-2CD2xxxG2, DS-2CD3xxxG2 (versions prior to V5.7.18 build240826)
- DS-2CD2xxxFWD (versions prior to V5.6.821 build240409)
Solution:
Hikvision has addressed this vulnerability by releasing updated firmware versions that enforce HTTPS communication with Dynamic DNS services. Users of affected cameras are strongly urged to update their firmware to the latest version as soon as possible.
Related Posts:
- Hikvision HikCentral Master Lite and Professional Affected by Multi Vulnerabilities
- CVE-2021-36260: Zero-click Hikvision cameras RCE flaw affects 80,000 devices
- Hikvision Patches Security Flaws (CVE-2024-25063 & 25064): Update Your HikCentral Pro
- The 7777-Botnet Exploit: A New Threat to TP-Link, Xiongmai, and Hikvision
- Hacker group Anonymous controls over 400 Russian cameras