An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.
The GV-IP Device Utility tool, when communicating with GeoVision devices on the network, sends privileged commands in the form of UDP broadcast packets containing encrypted user credentials. The encryption is based on a scheme derived from the Blowfish algorithm, however the symmetric key used for encryption is attached directly to the same packet. This means that the security of credentials relies solely on the secrecy of the encryption scheme (security through obscurity) rather than on key secrecy. A person eavesdropping on network traffic in the LAN segment — for example using a standard sniffer — can collect broadcast packets at the moment when an administrator uses the tool, and then independently implement the decryption algorithm and recover the login and password.
An attacker who recovers administrator credentials gains full control over the GeoVision device configuration — can change its IP address, restore factory settings, or perform other administrative operations.
Apply patches available from the manufacturer according to the references (https://www.geovision.com.tw/cyber_security.php). Until updated, it is recommended to restrict access to the network segment where the tool operates and avoid using GV-IP Device Utility in untrusted network environments.
GeoVision GV-IP Device Utility version 9.0.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:HGeovision Gv Ip Device Utility
APPGeovision9.0.5
Related vulnerabilities
OS Command Injection w urządzeniach GeoVision — zdalne wykonanie poleceń bez uwierzytelnienia
Command injection w urządzeniach GeoVision EOL — zdalne wykonanie poleceń
Command injection w GeoVision LPC2011/LPC2211 via konfiguracja DDNS
Privilege escalation w interfejsie Web GeoVision LPC2011/LPC2211
Stack overflow w GeoVision GV-VMS — nieuwierzytelnione RCE przez WebCam Server