Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Unpatched Dahua DVRs Pose Security Concerns

International. A few days ago, Ankit Anubhav, Principal Investigator at NewSky Security, revealed on Twitter that login passwords for tens of thousands of Dahua DVRs have been cached and indexed by IoT search engine ZoomEye. To make matters worse, this vulnerability, CVE-2013-6117, was initially discovered in 2013 with a firmware patch subsequently released by the company to fix it.

Despite numerous warnings from cybersecurity experts in recent years about the importance of patching IP physical security equipment against known vulnerabilities, it appears that that message has yet to be consolidated in some corners of the industry.

Last week, Ankit Anubhav, Principal Investigator at NewSky Security, revealed on Twitter that login passwords for tens of thousands of Dahua DVRs have been cached and indexed by IoT search engine ZoomEye. To make matters worse, this vulnerability, CVE-2013-6117, was initially discovered in 2013 with a firmware patch subsequently released by the company to fix it.

Even though they stopped their investigation after discovering the extent of the vulnerability and couldn't really say how many had already been compromised by the hackers, Scott Wu, co-founder and CEO of NewSky Security, which has a number of customers with enterprise IP camera systems in the Smart Cities and Smart Buildings sectors – says the potential impact for owners of these devices is obvious and that many of them are they are already "owned" by malicious actors or have a "critical risk" of being owned. In fact, Wu says he'd be surprised if not everyone is already engaged, considering how fast information moves in the underground Internet economy.

- Publicidad -

"It's a vulnerability of the DVR, which responds to querying credentials in plain text," Wu explains. "ZoomEye, as an IoT search engine similar to Shodan, stores and indexes search results, including credentials unfortunately given through the vulnerability."

For its part, Dahua issued a statement a few days ago asking the owners of the affected devices to update them and change their passwords. "We note that some media outlets recently reported on CVE-2013-6117, which was resolved in 2013. We strongly recommend customers using DVR versions before 2013 to update the device and change the password. The latest firmware can be downloaded from Dahua's website," the statement reads.

Dahua also encouraged everyone who has cybersecurity-related questions to contact the company via email at [email protected] 

Santiago Jaramillo
Author: Santiago Jaramillo
Editor
Comunicador social y periodista con más de 15 años de trayectoria en medios digitales e impresos, Santiago Jaramillo fue Editor de la revista "Ventas de Seguridad" entre 2013 y 2019.

No thoughts on “Unpatched Dahua DVRs Pose Security Concerns”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter