An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.
The tool, during communication with GeoVision devices on the network, sends privileged commands in the form of UDP broadcast packets containing encrypted authentication data. The encryption scheme applied is based on an algorithm similar to Blowfish; however, the symmetric key used for encryption is attached directly to the transmitted packet. This means that the security of the password and username relies solely on hiding the encryption mechanism (security through obscurity) rather than on key secrecy. An attacker on the same LAN network can intercept the broadcast packet when an administrator uses the tool, and then independently implement the algorithm and decrypt the credentials.
The attacker gains access to the GeoVision device administrator credentials, giving them full control over its configuration — including the ability to change the device IP address or restore it to factory settings.
Apply patches available from the manufacturer according to the references. As temporary remediation measures, it is recommended to restrict access to the LAN network where GeoVision devices operate, implement network segmentation (VLAN), and monitor UDP broadcast traffic for unauthorized eavesdropping.
GeoVision GV-IP Device Utility version 9.0.5 and GeoVision devices configured and managed using this tool.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H