CVE-2017-14953
HikVision Wi-Fi IP Camera Wireless Access Point State
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication. NOTE: Vendor states that this is not a vulnerability, but more an increase to the attack surface of the product
** EN DISPUTA ** Las cámaras IP HikVision, cuando se utilizan en una configuración por cable, permiten que los atacantes cercanos físicamente desencadenen la asociación con un punto de acceso arbitrario utilizando un SSID por defecto sin cifrado o autenticación de wifi. NOTA: El vendedor afirma que esto no es una vulnerabilidad, sino más bien un aumento de la superficie de ataque del producto.
HikVision Wi-Fi IP cameras come with a default SSID "davinci", with a setting of no WiFi encryption or authentication. Depending on the firmware version, there is no configuration option within the camera to turn off Wi-Fi. If a camera is deployed via wired ethernet, then the WiFi settings won't be adjusted, and a rogue AP with the SSID "davinci" can be associated to the camera to provide a new attack vector via WiFi to a wired network camera. Tested on firmware versions 5.3.0, 5.4.0, and 5.4.5 and model number DS-2CD2432F-IW.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2017-09-29 CVE Reserved
- 2017-11-28 CVE Published
- 2023-10-11 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-311: Missing Encryption of Sensitive Data
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/145131/HikVision-Wi-Fi-IP-Camera-Wireless-Access-Point-State.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2017/Nov/43 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hikvision Search vendor "Hikvision" | Ds-2cd2432f-iw Firmware Search vendor "Hikvision" for product "Ds-2cd2432f-iw Firmware" | < 5.4.5 Search vendor "Hikvision" for product "Ds-2cd2432f-iw Firmware" and version " < 5.4.5" | - |
Affected
| in | Hikvision Search vendor "Hikvision" | Ds-2cd2432f-iw Search vendor "Hikvision" for product "Ds-2cd2432f-iw" | - | - |
Safe
|