Milestone Open Network Bridge (ONVIF) security vulnerability
SUMMARY:
Milestone Systems has released a software update for XProtect® VMS which fixes a security vulnerability with unsecured credential storage when using Milestone Open Network Bridge (ONVIF). This vulnerability might result in an attacker reverse-engineering the stored credentials in the software component. Milestone recommends applying the available hotfix at the earliest possible opportunity.
AFFECTED PRODUCT AND VERSIONS:
Affected product and versions | Remediation |
|---|---|
product: XProtect Open Network Bridge versions: all currently supported versions (2018 R2 - 2020 R3) | Download and apply the universal hotfix provided by Milestone Systems — check KB 31968. |
WORKAROUNDS AND MITIGATIONS:
Milestone has determined these workarounds and mitigations that customers can use to reduce risk: disable the Open Network Bridge (ONVIF) if it is not required.
Note: The Open Network bridge is disabled by default.
GENERAL SECURITY RECOMMENDATIONS:
As a general security measure Milestone strongly recommends protecting network access to the affected products with appropriate mechanisms. It is advised to follow the recommendations in the Milestone Hardening Guide security practices to run the devices in a protected IT environment.
PRODUCT DESCRIPTION (Milestone Open Network Bridge):
Milestone Open Network Bridge is an open ONVIF-compliant interface for standardized and secure video sharing from XProtect VMS systems to other IP-based security systems. This enables law enforcement, surveillance centers, or similar organizations (referred to as ONVIF clients) to access live- and recorded H.264 video streams from your XProtect VMS system to their central monitoring solutions. The video streams are sent as RTSP streams over the Internet.
VULNERABILITY CLASSIFICATION:
The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1). The CVSS environmental score is specific to the customer's environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish the final scoring.
Vulnerability CVE-2021-27392
Affected Open Network Bridges store user credentials for the authentication between ONVIF clients and ONVIF server using a hard-coded key. The encrypted credentials can be retrieved via the MIP SDK. This could allow an authenticated remote attacker to retrieve and decrypt all credentials stored on the ONVIF server.
CVSS v3.1 Base Score 9.9
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE CWE-321: Use of Hard-coded Cryptographic Key
HOTFIX:
To download and apply the hotfix provided by Milestone Systems, check KB 31968: "Milestone Open Network Bridge (ONVIF) vulnerability (hotfix for XProtect 2018 R2 - 2020 R3)".
ADDITIONAL INFORMATION:
For further inquiries on security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team: https://www.milestonesys.com/da/support/tools-and-references/cyber-security/
HISTORY DATA:
This article is v. 1.0 and was first published on 13-Apr-2021.
Article Number