Security company warns that known vulnerabilities in Hikvision network cameras are being exploited by hackers



In July 2021, a command injection vulnerability was found in multiple network cameras manufactured by Hikvision, a Chinese manufacturer of surveillance cameras, etc., and products that have not been patched are crimes. has been reported to be abused by The security company that pointed out the problem warns that security companies are 'overwhelmed by hackers trying to exploit products that remain vulnerable.'

CYFIRMA Research - Hikvision Surveillance Cameras Vulnerabilities.pdf
(PDF file)

https://www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf

Experts warn of widespread exploitation involving Hikvision cameras - The Record by Recorded Future
https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/

According to security company CYFIRMA, a large number of hackers trying to exploit the vulnerability `` CVE-2021-36260 '' found in Hikvision network cameras have been confirmed on Russian criminal forums.

There are more than 80,000 cameras worldwide that have not been patched and may be attacked. Hikvision provides surveillance equipment for civilian and military use, with over 100 countries and over 2,300 organizations affected, CYFIRMA reported.

The country with the most cameras that remain vulnerable is China, with 12,690. The United States followed with 10,611 units, followed by Vietnam with 7,394 units.



Scored 9.8 out of 10, this highly critical vulnerability has been fixed by Hikvision and an update has been

distributed . However, there are many cameras with vulnerabilities even at the time of article creation, which has been almost a year since distribution, and there is a risk of being attacked. The U.S. Cybersecurity Infrastructure Security Agency has added this vulnerability to the ``List of Known Exploited Vulnerabilities'' and has ordered private institutions to apply patches by the end of August 2022.



in Posted by log1p_kr