Video encoders using Huawei chips have backdoors and bad bugs – and Chinese giant says it's not to blame
- Reference: 1600368132
- News link: https://www.theregister.co.uk/2020/09/17/huawei_iptv_video_encoder_security/
- Source link:
In a disclosure published this week, Alexei Kojenov, lead product security engineer at Salesforce, outlined a series of flaws affecting IPTV/H.264/H.265 video encoders powered by the hi3520d chipset from Huawei's HiSilicon subsidiary. The security holes are present in software, whose developer is unknown, that runs on top of a Linux stack provided by HiSilicon for products using its system-on-chips.
"The vulnerabilities exist in the application software running on these devices," said Kojenov in [1]his post . "All vulnerabilities are exploitable remotely and can lead to sensitive information exposure, denial of service, and remote code execution resulting in full takeover of the device."
The critical flaws include: an administrative interface with a backdoor password (CVE-2020-24215); root access via telnet (CVE-2020-24218); and unauthenticated file upload (CVE-2020-24217), which enables malicious code execution and command injection. All of these can be exploited over the network or internet to hijack vulnerable equipment. Kojenov also flagged vulnerabilities of high and medium severity: a buffer overflow (CVE-2020-24214) that stops the thing from working properly, and a way to access RTSP video streams without authorization (CVE-2020-24216).
Huawei insists the vulnerabilities were not introduced by its HiSilicon chips nor the SDK code it provides to manufacturers that use its components. That would mean someone else provided the makers of these video encoder devices application software riddled with holes, and this code was shipped with the equipment. The products just all happen to use the the hi3520d chipset.
In a statement emailed to The Register and [2]posted online , a Huawei spokesperson said, "Following the media reports about the suspected security issues (CVE-2020-24214, CVE-2020-24215, CVE-2020-24216, CVE-2020-24217, CVE-2020-24218, and CVE-2020-24219) in HiSilicon video surveillance chips on September 16, 2020, Huawei has launched an immediate investigation. After technical analysis, it was confirmed that none of the vulnerabilities were introduced by HiSilicon chips and SDK packages. Huawei is in favor of coordinated vulnerability disclosure by all organizations and individuals in the security research ecosystem to reduce the impact on stakeholders."
After technical analysis, it was confirmed that none of the vulnerabilities were introduced by HiSilicon chips and SDK packages
Huawei said all the vulnerabilities mentioned in the report reside in the application layer provided by the equipment vendors. "These vulnerabilities are not introduced by the chips and SDKs provided by HiSilicon," the Middle Kingdom giant said.
CMU's CERT Coordination Center [3]said the vulnerabilities exist in various network services running on various manufacturers' devices that use HiSilicon's parts, and are the result of software bugs, such as insufficient input validation and hardcoded credentials.
The encoders are used to stream video over IP networks, converting raw video signals to digital video using compression standards like H.264 or H.265 for distribution through a service like YouTube, or to be viewed directly in a web or app-based video player as an RTSP or HLS stream.
Kojenov says he analyzed video encoders from URayTech, J-Tech Digital, and Pro Video Instruments, and found their devices to be vulnerable to some or all of the reported flaws. He also identified several other vendors offering products based on the same system-on-chip, and he believes they may share some or all of the flaws: this includes equipment from Network Technologies Incorporated, Oupree, MINE Technology. Blankom, ISEEVY, Orivison, WorldKast/procoder, and Digicast.
Decoding the Chinese Super Micro super spy-chip super-scandal: What do we know – and who is telling the truth? [4]READ MORE
Kojenov said he notified various vendors but only one, Pro Video Instruments, took the notice seriously and responded. Most vendors, he said, have not yet issued a fix for these flaws. And in the absence of a patch, he advises that network admins make sure affected devices are behind a firewall with no externally exposed ports and with rules to block untrusted access.
He was able to find several hundred potentially vulnerable devices using the security-oriented search service shodan.io, and he expects these publicly exposed encoders are all exploitable over the internet.
"While most vulnerabilities seem unintentional (i.e. coding mistakes), one of them stands out," said Kojenov. "The hardcoded password is a deliberate backdoor."
In a message to The Register , he said all the vulnerabilities except for the telnet flaw resided in a single executable program that's part of the software on these devices. "I'm not sure the vendors who build and sell these devices have much control over it," he said. "I don't know if they have the source code for the program or it is distributed in binary form."
Taking Huawei’s representations at face value, we’re left to wonder where in the complicated manufacturing supply chain things went wrong. As Kojenov suggested in his report, most of the flaws appear to be unintentional coding mistakes. The fact that it’s not clear where these problems originated or who’s responsible should be at least as concerning as the specific risks posed by the bugs themselves.
Huawei maintains it wants to work toward better security.
"As an important part of the supply chain of video surveillance devices, HiSilicon is willing to collaborate with downstream equipment vendors and researchers through coordinated response to cyber security risks brought by the vulnerabilities mentioned in the report and protect the interests of end users," the tech goliath concluded. ®
Get our [5]Tech Resources
[1] https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
[2] https://www.huawei.com/en/psirt/security-notices/2020/huawei-sn-20200917-01-hisilicon-en
[3] https://www.kb.cert.org/vuls/id/896979
[4] https://www.theregister.com/2018/10/04/supermicro_bloomberg/
[5] https://whitepapers.theregister.com/
Re: "The hardcoded password is a deliberate backdoor."
True - and there have been quite a few other products from other manufactures that have had similar issues over the years.
Re: "The hardcoded password is a deliberate backdoor."
@"from other manufactures that have had similar issues over the years." quite, windows codecs were IMHO always a dodgy idea, especially where windows askes if you want to download "correct" codec to play dodgy video.
The issue here is a shame as my HuaWei phone has had monthly android security updates, something that I never seen with Samsung or HTC. HTC in my case never provided an update for my phone and when I contacted them they obsessed about me wanting to unlock the phone rather than addressing the issue that the phone was selected because of their "reprutation for software maintenance", apparantly it didnt apply to my marketting package from CarPhone Warehouse ehcen HTC added to me Sh1tL1st.
I would generally say that if the phone is vulnerable then the manufacturer should address it.
That being said from what I have seen from HuaWei, relative to every other phone maker I have used, HuaWei "were" IMHO the most likely to actually bother with a fix. "were" here because in my case the UK sucking up to the American/Trump "we cant compete with China so they can't sell to our bitches, y'all" doesn't leave much of an incentive for HuaWei.
Dear Huawei,
You get what you pay for so don't blame your suppliers. You chose them and the buck stop there.
Own your actions.
(And get another PR firm, the current PR supplier you've chosen also has "bugs" if this lame ass response is anything to go by)
@A/C
"Own your actions" you said, whilst posting as a anonymous coward.
Just saying.
Cheers… Ishy
Seems not Huawei's suppliers, but their customers. Behind the whole horrible China-based fly-by-night electronics hustle Huawei/HiSilicon just have the honour of being the only identifiable brand with some reputation to beat up on. If not for them would Arm be to blame?
The HiSilicon supplied SDKs are available here: https://dl.openipc.org/SDK/HiSilicon/
So it should be relatively straightforward to confirm their claim the bugs are indeed not theirs. Considering they describe the software as 'SDK' I'd assume all the Linux configuration issues aren't included.
Most likely some unknown 3rd party builds the SDK into a functioning OS and supplies minimally configurable firmware to a student working night-shift in a petrol station, who makes circuit diagrams and licenses those with the firmware to various solderers who in turn sell their bare boards to one of 40 different packaging shops all owned by three blokes who know the same dodgy geezer who knows where to get 'cheap plastic' (*wink* *wink*). From there they get branded by literally anyone capable of clicking the correct buttons on Alibaba to ask "I'd like 20 of these in red please with this logo on the side".
State Sponsored Industrial Sabotage
I wonder if someone infiltrated the supply chain to muck it up a bit, thereby solidifying their position that, "Huawei is bad, mmmkay."
Re: State Sponsored Industrial Sabotage
Occam's Razor suggests that the simplest explanation is likely the correct one.
Have you ever ridden a Chinese motorcycle?
Re: State Sponsored Industrial Sabotage
It doesn't surprise me that there is a lot of handy freeware floating around China to help Chinese industry get nice cheap stuff out there bringing in the foreign currency. And it doesn't surprise me when it is found to contain dodgy but potentially 'useful' code.
Supply chain?
Let me guess: Huawei stole the software from Hikvision and Hikvision can't even remember where their buggy pile of crap came from. The mystery software in Hikvision cameras is partially written in English so it must be a Western problem.
Corporate Sponsored Industrial Sabotage
When the west moved virtually all the production to China about 20 years ago it seems that nobody ever thought that China would be able to do the sort of things that No Such Agency is good at - there were discussions about this risk at the time, but the cheaper production costs were far more important than security - it's still that case, we see all these complaints but nobody ever suggests a solution, or is made responsible because they drove the stock prices up nicely.
We're blaming the Chinese for our stupidity in creating this environment.
Re: Corporate Sponsored Industrial Sabotage
We're blaming the Chinese for our stupidity in creating this environment.
While this situation was predictable, that doesn't absolve China of its responsibility.
"The hardcoded password is a deliberate backdoor."
Not a good look for a company wanting to have its kit accepted as secure and trustworthy with worldwide ambitions for its 5G kit.