PT-2021-7804 · Unknown · Siveillance Video Open Network Bridge
Published
2021-04-13
·
Updated
2022-04-25
·
CVE-2021-27392
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Siveillance Video Open Network Bridge versions 2018 R2 through 2020 R3
Description
A vulnerability has been identified in Siveillance Video Open Network Bridge, where affected Open Network Bridges store user credentials for authentication between ONVIF clients and ONVIF server using a hard-coded key. The encrypted credentials can be retrieved via the MIP SDK, allowing an authenticated remote attacker to retrieve and decrypt all credentials stored on the ONVIF server. This issue is related to the use of a hard-coded cryptographic key in the software.
Recommendations
For Siveillance Video Open Network Bridge versions 2018 R2 through 2020 R3, consider disabling the storage of user credentials for ONVIF authentication until a patch is available. Restrict access to the MIP SDK to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siveillance Video Open Network Bridge