Randorisec has released a blog detailing multiple Remote Code Execution (RCE) vulnerabilities in UDP Technology’s IP camera firmware, along with Proof-of-Concept (PoC) exploit code. Some of these are unpatched from earlier firmware releases and combined with a new authentication bypass. These apply to the firmware 1.12.0.27 and earlier versions, but are patched by the newest firmware release on June 30th. In addition to selling cameras under its own brand in Asia, UDP Tech supplies for the firmware for a number of security/IP camera vendors including: Geutebruck, Ganz, Visualint, Cap, THRIVE Intelligence, Sophus, VCA, TripCorps, Sprinx Technologies, Smartec, and Riva. A root shell will allow a foothold with persistence onto the network, as well as full access to the camera’s data and ongoing video stream.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security