¡¾Îó²îͨ¸æ¡¿´ó»ªIPÉãÏñÍ·ÖØ·ÅÎó²î£¨CVE-2022-30563£©

Ðû²¼Ê±¼ä 2022-08-01

 

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2022-30563

·¢Ã÷ʱ¼ä

2022-08-01

Àà    ÐÍ

ÖØ·Å¹¥»÷

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

¸ß

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

Õã½­´ó»ªÊÖÒչɷÝÓÐÏÞ¹«Ë¾ÊÇÁìÏÈµÄ¼à¿Ø²úÆ·¹©Ó¦ÉÌÏ¢Õù¾ö¼Æ»®ÌṩÉÌ£¬ £¬£¬ÃæÏòÈ«ÇòÌṩÁìÏȵÄÊÓÆµ´æ´¢¡¢Ç°¶Ë¡¢ÏÔʾ¿ØÖƺÍÖÇÄܽ»Í¨µÈϵÁл¯²úÆ·¡£ ¡£¡£¡£¡£¡£

6ÔÂ28ÈÕ£¬ £¬£¬´ó»ªÐû²¼Ç徲ͨ¸æ£¬ £¬£¬ÐÞ¸´ÁËÆä¶à¸ö²úÆ·ÖеÄ4¸öÇå¾²Îó²î£¬ £¬£¬ÏêÇéÈçÏ£º

CVE-ID

ÆÀ·Ö

˵Ã÷

CVE-2022-30560

5.4

µ±»ñÈ¡ÖÎÀíÕʺźÍÃÜÂëʱ£¬ £¬£¬»òÕßͨ¹ýÖÐÐÄÈ˹¥»÷£¬ £¬£¬¿ÉÒÔÏòÒ×Êܹ¥»÷µÄ½Ó¿Ú·¢ËÍÖ¸¶¨µÄÌØÖÆÊý¾Ý°ü£¬ £¬£¬´Ó¶øµ¼ÖÂ×°±¸Í߽⡣ ¡£¡£¡£¡£¡£

CVE-2022-30561

5.9

µ±Ê¹ÓÃÖÐÐÄÈ˹¥»÷Ðá̽ÇëÇó°ü²¢ÀֳɵǼʱ£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖØ·ÅÓû§µÄµÇ¼°üÀ´µÇ¼װ±¸¡£ ¡£¡£¡£¡£¡£

CVE-2022-30562

3.7

ÈôÊÇÓû§ÔÚ×°±¸ÉÏ¿ªÆôÁËhttps¹¦Ð§£¬ £¬£¬Ôò¿ÉÒÔͨ¹ýÖÐÐÄÈ˹¥»÷ÐÞ¸ÄÓû§µÄÇëÇóÊý¾Ý°ü£¬ £¬£¬Öض¨Ïòµ½¶ñÒâÒ³Ãæ¡£ ¡£¡£¡£¡£¡£

CVE-2022-30563

6.8

µ±Ê¹ÓÃÖÐÐÄÈ˹¥»÷Ðá̽ͨ¹ýONVIFÀֳɵǼµÄÇëÇó°üʱ£¬ £¬£¬¿ÉÒÔͨ¹ýÖØ·ÅÓû§µÄµÇ¼°üÀ´µÇ¼װ±¸¡£ ¡£¡£¡£¡£¡£

ÆäÖÐCVE-2022-30563µÄϸ½ÚÒѾ­¹ûÕæÅû¶£¬ £¬£¬¸ÃÎó²î±£´æÓÚ´ó»ªÄ³Ð©IPÉãÏñÍ·µÄONVIF WS-UsernameTokenÈÏÖ¤»úÖÆÊµÑéÖУ¬ £¬£¬µ±Ê¹ÓÃÖÐÐÄÈ˹¥»÷Ðá̽ͨ¹ýONVIFÀֳɵǼÇÒδ¼ÓÃܵÄÇëÇó°üʱ£¬ £¬£¬¿ÉÒÔͨ¹ýÔÚеÄÇëÇóÖÐÖØ·ÅÓû§µÇ¼°üÖÐµÄÆ¾Ö¤À´ÊµÏֵǼºÍ¿ØÖÆ×°±¸¡£ ¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

´ó»ªASI7XXX£ºv1.000.0000009.0.R.220620֮ǰµÄ°æ±¾£¨¹¹½¨Ê±¼äÔÚ 2021 Äê 9 ÔÂ֮ǰµÄ°æ±¾£©

´ó»ªIPC-HDBW2XXX£ºv2.820.0000000.48.R.220614֮ǰµÄ°æ±¾£¨¹¹½¨Ê±¼äÔÚ 2022 Äê 4 ÔÂ֮ǰµÄ°æ±¾£©

´ó»ªIPC-HX2XXX£ºv2.820.0000000.48.R.220614֮ǰµÄ°æ±¾£¨¹¹½¨Ê±¼äÔÚ 2022 Äê 4 ÔÂ֮ǰµÄ°æ±¾£©

 

0x02 Çå¾²½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬ £¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔÏÂÐÞ¸´°æ±¾£¬ £¬£¬»òÁªÏµÍâµØÊÖÒÕÖ§³Ö¾ÙÐÐÉý¼¶£º

´ó»ªASI7XXX£º

DH_ASI72XXX_Eng_NP_V1.000.0000009.0.R.220620.zip

´ó»ªIPC-HDBW2XXX£º

DH_IPC-HX2XXX-Molec_MultiLang_PN_V2.820.0000000.48.R.220614.zip

´ó»ªIPC-HX2XXX£º

DH_IPC-HX2XXX-Molec_MultiLang_NP_V2.820.0000000.48.R.220614.zip

ÏÂÔØÁ´½Ó£º

https://www.dahuasecurity.com/support/downloadCenter

×¢£º¿ÉµÇ¼װ±¸Web½çÃæÉó²é¹¹½¨Ê±¼ä£¬ £¬£¬¿ÉÔÚÉèÖÃ-ϵͳÐÅÏ¢-°æ±¾ÐÅÏ¢Ò³Ãæ£¨setting-systeminfo-version£©Éó²é¡£ ¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.dahuasecurity.com/support/cybersecurity/details/1017

https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/

https://thehackernews.com/2022/07/dahua-ip-camera-vulnerability-could-let.html

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-08-01

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬ £¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£ ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬠£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬ £¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£ ¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ £¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£ ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£ ¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ £¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬ £¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬ £¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£ ¡£¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£ ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬ £¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png