PT-2021-7804 · Unknown · Siveillance Video Open Network Bridge

Published

2021-04-13

·

Updated

2022-04-25

·

CVE-2021-27392

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Siveillance Video Open Network Bridge versions 2018 R2 through 2020 R3
Description A vulnerability has been identified in Siveillance Video Open Network Bridge, where affected Open Network Bridges store user credentials for authentication between ONVIF clients and ONVIF server using a hard-coded key. The encrypted credentials can be retrieved via the MIP SDK, allowing an authenticated remote attacker to retrieve and decrypt all credentials stored on the ONVIF server. This issue is related to the use of a hard-coded cryptographic key in the software.
Recommendations For Siveillance Video Open Network Bridge versions 2018 R2 through 2020 R3, consider disabling the storage of user credentials for ONVIF authentication until a patch is available. Restrict access to the MIP SDK to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02956
CVE-2021-27392

Affected Products

Siveillance Video Open Network Bridge