• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • COVID-19 Update
  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
Compliance, IT Infrastructure, Network Security, News

Vulnerability Discovered in Dahua’s ONVIF Implementation

The vulnerability could be abused by attackers to access Dahua cameras with full privileges, including watching live video footage.

August 5, 2022 TD Staff Leave a Comment

Vulnerability Dahua ONVIF
JaizAnuar/stock.adobe.com

Cybersecurity firm Nozomi Networks recently revealed it had discovered a new vulnerability affecting the implementation of an Open Network Video Interface Forum (ONVIF) authentication mechanism in some IP cameras developed by Dahua Technology.

According to a blog post by the cyber experts, this vulnerability could be abused by attackers to compromise Dahua network cameras by sniffing a previous unencrypted ONVIF interaction and replaying the credentials in a new request towards the camera.

ONVIF is an open industry forum that provides and promotes standardized interfaces for effective interoperability of IP-based physical security products.

In order to communicate between products, ONVIF sends requests through XML SOAP messages via HTTP. One authentication mechanism ONVIF uses is WS-UsernameToken, which relies on the transmission of the username for a certified user, nonce (a random, unique number generated by a client), created (the UtcTime when the request is made) and a password to authenticate a request.

In its investigation, Nozomi Networks was able to forge a CreateUsers request to be added to an IPC-HDBW2231E-S-S2 dome network camera as an attacker-controlled administrator. It was then able to sniff an unencrypted ONVIF request authenticated with the WS-UsernameToken schema.

After creating the attacker-controlled administrator, researchers were able to use the account to access the Dahua device with full privileges, including watching live footage from the camera.

The firm says sniffing an unencrypted ONVIF request authenticated with the WS-UsernameToken schema is not an uncommon condition due to the following reasons:

  1. WS-UsernameToken is still used by default by many popular ONVIF clients, such as ONVIF Device Manager, or DSE VMS.
  2. By default, the IPC-HDBW2231E-S-S2 (like other Dahua devices) does not expose an HTTPS service, and all ONVIF interactions occur through unencrypted HTTP.

Nozomi Networks says in the real world, asset owners should not using the default WS credentials and use HTTPS for secure connections in order to prevent such an attack from occurring.

Upon notification of the vulnerability, Dahua released a patch at the end of June. When reached for comment, Dahua told SSI, “On 6-28-22 we released a security notice, which you can find here.  As of today (1 August) Dahua has released firmware patches that address these vulnerabilities.”

This article originally appeared on MyTechDecisions’ sister-site Security Sales & Integration. 

Tagged With: Cybersecurity, Dahua Technology, ONVIF, Video Surveillance Technology

Related Content:

  • Avocor W Series 8 All-in-One Videoconferencing Displays That Make Meetings Easier
  • DTEN ONboard DTEN Launches ONboard for Zoom Whiteboard
  • GoTo Connect, GoTo Resolve GoTo Brings IT Helpdesk Support to GoTo Connect
  • Zoom macOS Update Zoom on macOS Devices Now

Free downloadable guide you may like:

  • Shadow ITBlueprint Series: How to Reduce Shadow IT

    The distributed work model gives employees the flexibility they demand, but it can lead to shadow IT and introduce unnecessary security risk. Research finds that this distributed work environment is leading to IT management blind spots and shadow IT.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Shadow IT
Blueprint Series: How to Reduce Shadow IT

The distributed work model gives employees the flexibility they demand, but it can lead to shadow IT and introduce unnecessary security risk. Resea...

Hybrid Work webinar
Featured Webcast: Collaboration 2.0 — Where Are We Now?

In this webinar, subject matter experts discuss the transformation of the workplace, the rise of hybrid workers, the importance of open connectivit...

guide to end user training cover
Pro Tips for Conducting End User Training

Effective trainings are the glue that can make the difference following a new technology implementation that your team has spent so much time, effo...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2022 Emerald X, LLC. All rights reserved.