CERT-In Advisory
CIAD-2023-0007
Multiple Vulnerabilities in CCTV IP Camera and related Products
Original Issue Date: March 17, 2023
Updated: June 22, 2023
Severity Rating: High
Systems Affected
- Hikvision
- Dahua
- Bosch
- Mobotix
- Milesight
- ABUS
Overview
Multiple vulnerabilities have been reported in various CCTV IP Camera and related products which could be exploited by an attacker to access sensitive information, bypass security restrictions, perform a denial of service (DoS) attack, escalating privileges, perform Spoofing attacks or execute arbitrary codes on the targeted system.
Description
Multiple vulnerabilities have been reported in various CCTV IP Camera and related products; details of which are provided below:

Solution
- Apply appropriate firmware updates as provided in the OEM advisories
- Contact your Camera Vendors for the firmware update.
- Perform thorough vulnerability assessment of CCTV IP Camera equipment and network on regular basis.
Vendor Information
Hikvision
https://www.hikvision.com/en/support/cybersecurity/security-advisory/access-control-vulnerability-in-some-hikvision-wireless-bridge-products/
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-hybrid-san-products/
Dahua
https://www.dahuasecurity.com/support/cybersecurity/details/1137
https://www.dahuasecurity.com/support/cybersecurity/details/1147
Bosch
https://psirt.bosch.com/security-advisories/bosch-sa-464066-bt.html
Mobotix
https://www.mobotix.com/en/software-downloads
Milesight
https://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view
CVE Name
CVE-2022-28173
CVE-2022-28172
CVE-2022-45431
CVE-2022-45429
CVE-2022-45423
CVE-2022-45425
CVE-2022-45427
CVE-2022-30564
CVE-2022-47648
CVE-2022-32540
CVE-2022-30018
CVE-2022-3001
CVE-2023-26609
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|