Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability in Xiongmai IP Camera firmware could allow unauthorized remote access to critical functions. It impacts the Sofia IPC daemon's WS-Security routine, potentially enabling attackers to bypass authentication and control camera operations. The main concern is confirming relevance and exposure to business systems.
- Bypasses camera security for remote control.
- Affects widely deployed IP camera systems.
- Confirm relevance and exposure to business systems.
Attack Path
How an attacker could exploit the issue
An attacker can remotely send a specially crafted SOAP request to a vulnerable IP camera's Sofia IPC daemon. This request exploits a flaw in how the device verifies WS-Security usernames and tokens, allowing the attacker to bypass authentication. If successful, the attacker can then perform unauthorized privileged actions on the camera, such as controlling its movement, obtaining video stream information, or even restarting the device.
- Accessible over the network.
- Crafted SOAP request with valid username.
- Unauthorized privileged actions.
Live Threat
Current exploitation, exposure, and threat context
An improper authentication vulnerability in the Sofia IPC daemon could allow unauthenticated remote attackers to bypass security controls and perform privileged actions on Xiongmai IP Camera firmware. This could occur when an account's stored password is empty, enabling attackers to execute commands like retrieving stream URLs, controlling pan-tilt-zoom, or rebooting the system by sending a crafted SOAP request.
- IP camera system control.
- Bypass authentication via crafted SOAP requests.
- Unauthorized access and system disruption.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in the Xiongmai IP Camera firmware likely impacts device owners and the teams responsible for managing networked IoT devices. The first practical step is to identify all deployed cameras, confirm their network exposure and business criticality, and then locate the accountable owner to plan remediation or mitigation strategies, potentially involving vendor coordination for firmware updates.
- Identify and confirm device ownership.
- Verify network exposure and criticality.
- Plan remediation or vendor engagement.