Overview
Dedicated Micros DVR products, including the DV-IP Express, SD Advanced, SD, EcoSense, and DS2, by default use plaintext protocols and require no password.
Description
CWE-311: Missing Encryption of Sensitive Data Dedicated Micros DVR products by default use HTTP, telnet, and FTP rather than secure alternatives, making it the responsibility of the end user to configure a device securely. Sensitive data may be viewed or modified in transit by unauthorized attackers. |
Impact
A remote, unauthenticated attacker can view and manipulate sensitive data and take complete control of an unsecured device. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem and recommends the following workarounds. |
Enable secure communications protocols
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 8.5 | E:POC/RL:W/RC:C |
Environmental | 6.4 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.dedicatedmicros.com/europe/products_group.php?product_group_id=1
- http://cybergibbons.com/security-2/shodan-searches/interesting-shodan-searches-sd-advanced-dvrs/
- https://www.shodan.io/search?query=command+line+processor+-username
- http://cwe.mitre.org/data/definitions/284.html
- http://cwe.mitre.org/data/definitions/311.html
Acknowledgements
Thanks to Andrew Tierney for reporting this vulnerability.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-2909 |
Date Public: | 2015-08-20 |
Date First Published: | 2015-08-20 |
Date Last Updated: | 2015-08-20 14:30 UTC |
Document Revision: | 22 |