¡¾Îó²îͨ¸æ¡¿´ó»ªIPÉãÏñÍ·ÖØ·ÅÎó²î£¨CVE-2022-30563£©

Ðû²¼Ê±¼ä 2022-08-01

 

0x00 Îó²î¸ÅÊö

CVE   ID

CVE-2022-30563

·¢Ã÷ʱ¼ä

2022-08-01

Àà    ÐÍ

ÖØ·Å¹¥»÷

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

¸ß

Óû§½»»¥

ÎÞ

PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

Õã½­´ó»ªÊÖÒչɷÝÓÐÏÞ¹«Ë¾ÊÇÁìÏÈµÄ¼à¿Ø²úÆ·¹©Ó¦ÉÌÏ¢Õù¾ö¼Æ»®ÌṩÉÌ £¬ £¬£¬ÃæÏòÈ«ÇòÌṩÁìÏȵÄÊÓÆµ´æ´¢¡¢Ç°¶Ë¡¢ÏÔʾ¿ØÖƺÍÖÇÄܽ»Í¨µÈϵÁл¯²úÆ·¡£¡£¡£¡£ ¡£

6ÔÂ28ÈÕ £¬ £¬£¬´ó»ªÐû²¼Ç徲ͨ¸æ £¬ £¬£¬ÐÞ¸´ÁËÆä¶à¸ö²úÆ·ÖеÄ4¸öÇå¾²Îó²î £¬ £¬£¬ÏêÇéÈçÏ£º

CVE-ID

ÆÀ·Ö

˵Ã÷

CVE-2022-30560

5.4

µ±»ñÈ¡ÖÎÀíÕʺźÍÃÜÂëʱ £¬ £¬£¬»òÕßͨ¹ýÖÐÐÄÈ˹¥»÷ £¬ £¬£¬¿ÉÒÔÏòÒ×Êܹ¥»÷µÄ½Ó¿Ú·¢ËÍÖ¸¶¨µÄÌØÖÆÊý¾Ý°ü £¬ £¬£¬´Ó¶øµ¼ÖÂ×°±¸Í߽⡣¡£¡£¡£ ¡£

CVE-2022-30561

5.9

µ±Ê¹ÓÃÖÐÐÄÈ˹¥»÷Ðá̽ÇëÇó°ü²¢ÀֳɵǼʱ £¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖØ·ÅÓû§µÄµÇ¼°üÀ´µÇ¼װ±¸¡£¡£¡£¡£ ¡£

CVE-2022-30562

3.7

ÈôÊÇÓû§ÔÚ×°±¸ÉÏ¿ªÆôÁËhttps¹¦Ð§ £¬ £¬£¬Ôò¿ÉÒÔͨ¹ýÖÐÐÄÈ˹¥»÷ÐÞ¸ÄÓû§µÄÇëÇóÊý¾Ý°ü £¬ £¬£¬Öض¨Ïòµ½¶ñÒâÒ³Ãæ¡£¡£¡£¡£ ¡£

CVE-2022-30563

6.8

µ±Ê¹ÓÃÖÐÐÄÈ˹¥»÷Ðá̽ͨ¹ýONVIFÀֳɵǼµÄÇëÇó°üʱ £¬ £¬£¬¿ÉÒÔͨ¹ýÖØ·ÅÓû§µÄµÇ¼°üÀ´µÇ¼װ±¸¡£¡£¡£¡£ ¡£

ÆäÖÐCVE-2022-30563µÄϸ½ÚÒѾ­¹ûÕæÅû¶ £¬ £¬£¬¸ÃÎó²î±£´æÓÚ´ó»ªÄ³Ð©IPÉãÏñÍ·µÄONVIF WS-UsernameTokenÈÏÖ¤»úÖÆÊµÑéÖÐ £¬ £¬£¬µ±Ê¹ÓÃÖÐÐÄÈ˹¥»÷Ðá̽ͨ¹ýONVIFÀֳɵǼÇÒδ¼ÓÃܵÄÇëÇó°üʱ £¬ £¬£¬¿ÉÒÔͨ¹ýÔÚеÄÇëÇóÖÐÖØ·ÅÓû§µÇ¼°üÖÐµÄÆ¾Ö¤À´ÊµÏֵǼºÍ¿ØÖÆ×°±¸¡£¡£¡£¡£ ¡£

 

Ó°Ïì¹æÄ£

´ó»ªASI7XXX£ºv1.000.0000009.0.R.220620֮ǰµÄ°æ±¾£¨¹¹½¨Ê±¼äÔÚ 2021 Äê 9 ÔÂ֮ǰµÄ°æ±¾£©

´ó»ªIPC-HDBW2XXX£ºv2.820.0000000.48.R.220614֮ǰµÄ°æ±¾£¨¹¹½¨Ê±¼äÔÚ 2022 Äê 4 ÔÂ֮ǰµÄ°æ±¾£©

´ó»ªIPC-HX2XXX£ºv2.820.0000000.48.R.220614֮ǰµÄ°æ±¾£¨¹¹½¨Ê±¼äÔÚ 2022 Äê 4 ÔÂ֮ǰµÄ°æ±¾£©

 

0x02 Çå¾²½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´ £¬ £¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔÏÂÐÞ¸´°æ±¾ £¬ £¬£¬»òÁªÏµÍâµØÊÖÒÕÖ§³Ö¾ÙÐÐÉý¼¶£º

´ó»ªASI7XXX£º

DH_ASI72XXX_Eng_NP_V1.000.0000009.0.R.220620.zip

´ó»ªIPC-HDBW2XXX£º

DH_IPC-HX2XXX-Molec_MultiLang_PN_V2.820.0000000.48.R.220614.zip

´ó»ªIPC-HX2XXX£º

DH_IPC-HX2XXX-Molec_MultiLang_NP_V2.820.0000000.48.R.220614.zip

ÏÂÔØÁ´½Ó£º

https://www.dahuasecurity.com/support/downloadCenter

×¢£º¿ÉµÇ¼װ±¸Web½çÃæÉó²é¹¹½¨Ê±¼ä £¬ £¬£¬¿ÉÔÚÉèÖÃ-ϵͳÐÅÏ¢-°æ±¾ÐÅÏ¢Ò³Ãæ£¨setting-systeminfo-version£©Éó²é¡£¡£¡£¡£ ¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.dahuasecurity.com/support/cybersecurity/details/1017

https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/

https://thehackernews.com/2022/07/dahua-ip-camera-vulnerability-could-let.html

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-08-01

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Äê £¬ £¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£ ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£ ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏà £¬ £¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË £¬ £¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£ ¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ £¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬ £¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ £¬ £¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ £¬ £¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£ ¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£ ¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬ £¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png