CVE-2017-7921
9.5 CISA KEVHikvision · IP Cameras
An improper authentication vulnerability exists in various Hikvision IP cameras, allowing unauthenticated attackers to bypass login controls and escalate privileges via a logic error.
Executive summary
This critical improper authentication vulnerability in Hikvision IP cameras is being actively exploited in the wild and requires immediate firmware remediation to prevent unauthorized system access.
Vulnerability
The flaw is an improper authentication vulnerability (CWE-287) where the application fails to correctly authenticate users. Unauthenticated remote attackers can exploit this via a logic error involving a Base64 encoded query parameter to gain full administrative privileges.
Business impact
Successful exploitation grants an attacker full control over the affected camera, leading to the compromise of sensitive video feeds, configuration data, and user credentials. With a CVSS score of 9.5, this vulnerability represents a severe risk to physical security and network integrity, as compromised cameras can be leveraged as persistent entry points into broader internal networks.
Remediation
Immediate Action: Update affected devices to the corresponding patched firmware versions: V5.4.5 build 170123 (DS-2CD2xx2F-I/DS-2CD2xx0F-I), V5.4.5 build 170124 (DS-2CD2xx2FWD), V5.4.5 build 170228 (DS-2CD4x2xFWD), V5.4.5 build 170302 (DS-2CD4xx5), V5.4.9 build 170123 (DS-2DFx), or V5.4.5 build 170206 (DS-2CD63xx).
Proactive Monitoring: Monitor network traffic for unusual outbound connections from camera devices and audit logs for unauthorized access attempts or configuration changes.
Compensating Controls: If patching is not immediately feasible, isolate affected cameras from the public internet using firewalls or VPNs to restrict access to authorized management segments only.
Exploitation status
Public Exploit Available: Yes, a weaponized exploit exists, including Metasploit modules and Nuclei detection templates.
Analyst recommendation
Given the confirmed active exploitation and the critical severity of this vulnerability, organizations must treat this as a high-priority remediation task. Failure to apply the vendor-provided firmware updates leaves the environment exposed to unauthorized surveillance and potential lateral movement by sophisticated threat actors. Immediate patching or network isolation of all vulnerable Hikvision units is strongly advised.
More Hikvision CVEs
Sources
- ics-cert.us-cert.gov
- 98313 Vulnerability database entry
- ghostbin.com
- hikvision.com