vendor:
Hikvision Camera
by:
Alfie
7.5
CVSS
HIGH
User Enumeration
CWE
Product Name: Hikvision Camera
Affected Version From: V5.2.0 build 140721
Affected Version To: V5.4.0 build 160530
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2018
Hikvision IP Camera 5.4.0 – User Enumeration (Metasploit)
Many Hikvision IP cameras contain a backdoor that allows unauthenticated impersonation of any configured user account. The vulnerability has been present in Hikvision products since at least 2014. In addition to Hikvision-branded devices, it affects many white-labeled camera products sold under a variety of brand names. Hundreds of thousands of vulnerable devices are still exposed to the Internet at the time of publishing. In addition to gaining full administrative access, the vulnerability can be used to retrieve plain-text passwords for all configured users.
Mitigation:
Update to the latest firmware version. Limit exposure of the camera to the Internet by placing it behind a firewall or on a private network.