{"id":4883,"date":"2022-08-30T00:11:33","date_gmt":"2022-08-29T22:11:33","guid":{"rendered":"https:\/\/www.ass-security.fr\/blog\/?p=4883"},"modified":"2025-02-16T18:47:53","modified_gmt":"2025-02-16T17:47:53","slug":"vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260","status":"publish","type":"post","link":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/","title":{"rendered":"News : Vuln\u00e9rabilit\u00e9 critique not\u00e9e par le CVSS 9,8 pour les cam\u00e9ras de vid\u00e9osurveillance Hikvision &#8211; Faille CVE-2021-36260"},"content":{"rendered":"\n<p>Une faille <strong>RCE &#8211; Remote Code Execution<\/strong> affecte la plupart des cam\u00e9ras de surveillance Hikvision construite \u00e0 partir de 2016 jusqu\u2019\u00e0 aujourd\u2019hui (<strong>hors cam\u00e9ras patch\u00e9es apr\u00e8s septembre 2021<\/strong>). Les failles RCE sont des vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 logicielle permettant l\u2019ex\u00e9cution d\u2019un code malveillant en local ou \u00e0 distance vers l\u2019\u00e9quipement concern\u00e9. Une faille laissant envisager une possibilit\u00e9 de \u00ab\u2009<strong>Zero Day<\/strong>\u2009\u00bb ayant probablement \u00e9t\u00e9 exploit\u00e9e de mani\u00e8re obscure bien des ann\u00e9es avant sa d\u00e9couverte le 21 juin 2021. Cette vuln\u00e9rabilit\u00e9 toucherait plusieurs <strong>centaines de millions de <a href=\"https:\/\/www.ass-security.fr\/blog\/?s=hikvision\">produits Hikvision<\/a><\/strong> dans le monde incluant, les NVR\/DVR \u00e9galement impact\u00e9s par cette faille du num\u00e9ro 1 mondial de la vid\u00e9osurveillance. Avec un <strong>score de 9,8<\/strong> sur une \u00e9chelle de 1 \u00e0 10 du syst\u00e8me d\u2019\u00e9valuation standardis\u00e9 \u00ab\u2009<strong>Common Vulnerability Scoring System \u2013 CVSS<\/strong>\u2009\u00bb, nul doute \u00e0 avoir que cette vuln\u00e9rabilit\u00e9 est consid\u00e9r\u00e9e comme critique&#8230; Hi\u00e9rarchis\u00e9e sous le num\u00e9ro \u00ab\u2009<strong>CVE-2021-36260<\/strong>\u2009\u00bb, cette faille d\u00e9couverte le 20 juin 2021 par <strong>@Watchful_IP<\/strong> aura \u00e9t\u00e9 transmise de mani\u00e8re d\u00e9taill\u00e9e et document\u00e9e au service <strong>HSRC Hikvision &#8211; Hikvision Security Response Center<\/strong>. S\u2019en suivront des \u00e9changes jusqu\u2019\u00e0 la publication d\u2019un bulletin d\u2019alerte fait par Hikvision (<strong>SN No. : HSRC-202109-01<\/strong>) et Watchful_IP le <strong>18 septembre 2021<\/strong>. S\u2019appuyant sur un acc\u00e8s Root complet (sup\u00e9rieur \u00e0 de simples privil\u00e8ges administrateur bien plus limit\u00e9) avec, une possibilit\u00e9 d\u2019ex\u00e9cution de commandes Shell racine b\u00e9n\u00e9ficiant des pleins privil\u00e8ges, cette vuln\u00e9rabilit\u00e9 semble v\u00e9ritablement d\u00e9passer toute <strong>esp\u00e9rance en mati\u00e8re de faille<\/strong>\u2026 <\/p>\n\n\n\n<figure class=\"wp-block-pullquote has-medium-font-size\"><blockquote><p>\u00ab Security Notification &#8211; Command Injection Vulnerability in Some Hikvision products<br>Read more: https:\/\/hikvision.com\/en\/support\/cybersecurity\/security-advisory\/security-notification-command-injection-vulnerability-in-some-hikvision-products #cybersecurity #Hikvision \u00bb<\/p><cite>HikvisionHQ (@HikvisionHQ) &#8211; Sept 19, 2021 &#8211; Twitter<\/cite><\/blockquote><\/figure>\n\n\n\n<p>Cet <strong>acc\u00e8s root<\/strong> permet l\u2019entier contr\u00f4le de l\u2019\u00e9quipement et de surcro\u00eet, la possibilit\u00e9 d\u2019ex\u00e9cution de code malveillant au sein d\u2019une <strong>cam\u00e9ra ou NVR Hikvision<\/strong> laissant l\u00e0, de tr\u00e8s belles opportunit\u00e9s \u00e0 tout type <strong>d\u2019individus malveillant<\/strong>\u2026. L&rsquo;exploitation de Botnets s&rsquo;av\u00e8re possible selon les diff\u00e9rentes documentations, principalement l\u2019ex\u00e9cution d&rsquo;un hybride baptis\u00e9 \u00ab\u2009<strong>Moobot<\/strong>\u2009\u00bb, issu d&rsquo;une g\u00e9n\u00e9tique proche de Mirai . Autant dire les ambitions d\u2019exploitation des produits Hikvision \u00e0 des fins de propagation de ce Botnet dans le but d\u2019ex\u00e9cuter des <strong>attaques DDoS<\/strong> n\u2019est plus \u00e0 prouver\u2026 Selon l\u2019\u00e9valuation des risques faite par <strong>Watchful_IP<\/strong> en 2021 sur son site internet, cette faille est exploitable \u00e0 distance ou en local sans n\u00e9cessiter la moindre authentification tout en ne laissant aucune trace d\u2019effraction dans les logs, rendant les attaques des plus discr\u00e8tes\u2026 L\u2019\u00e9quipement concern\u00e9 pourrait \u00eatre rendu inutilisable et la <strong>compromission des identifiants\/mdp<\/strong> est bien s\u00fbr, totalement possible. <strong>L\u2019ex\u00e9cution de code malveillant<\/strong> pourrait apporter un joli statut de \u00ab\u2009Machine-zombie\u2009\u00bb faisant de n\u2019importe quel \u00e9quipement de vid\u00e9osurveillance, une menace fant\u00f4me aux ordres de son commandant. Une m\u00e9thodologie qui n\u2019est pas sans rappeler l\u2019attaque de 2016 perp\u00e9tr\u00e9s contre le g\u00e9ant fran\u00e7ais OVH\u2026 <strong>Une attaque par D\u00e9ni de service &#8211; DDoS<\/strong> initi\u00e9 par plus de <strong>145 000 cam\u00e9ras de surveillance<\/strong> compromises qui, avec des <strong>salves stratosph\u00e9riques \u00e0 1 Tb\/s<\/strong>, avaient quelque peu d\u00e9fray\u00e9 la chronique \u00e0 l\u2019\u00e9poque !<\/p>\n\n\n\n<figure class=\"wp-block-pullquote has-medium-font-size\"><blockquote><p>\u00ab This botnet with 145607 cameras\/dvr (1-30Mbps per IP) is able to send &gt;1.5Tbps DDoS. Type : tcp\/ack, tcp\/ack+psh, tcp\/syn. \u00bb<\/p><cite>Octave Klaba\/Oles (@olesovhcom) &#8211; Sept 23, 2016 &#8211; Twitter<\/cite><\/blockquote><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"288\" data-src=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6-1024x288.png\" alt=\"\" class=\"wp-image-6483 lazyload\" data-srcset=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6-1024x288.png 1024w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6-500x141.png 500w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6-768x216.png 768w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6-1536x432.png 1536w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6-860x242.png 860w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/12\/image-6.png 1600w\" data-sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/288;\" \/><figcaption class=\"wp-element-caption\"><em>Extrait des captures d&rsquo;image publi\u00e9 par <strong>@Watchful_IP<\/strong>. L&rsquo;acc\u00e8s Root \u00e0 la cam\u00e9ra est visible sur cette capture depuis Kali Linux<\/em><\/figcaption><\/figure>\n\n\n\n<p>L&rsquo;autre <strong>volet obscur<\/strong> li\u00e9 \u00e0 l\u2019existence de ce type de vuln\u00e9rabilit\u00e9, r\u00e9side dans la possibilit\u00e9 de <strong>cyberattaque par \u00ab\u2009rebonds\u2009\u00bb<\/strong> avec des risques \u00e9ventuels de compromission du r\u00e9seau interne qui pourrait faciliter cette m\u00e9thodologie d&rsquo;attaque aussi connue sous l&rsquo;appellation <strong>\u00ab<\/strong> <strong>d&rsquo; Island\u2009Hopping \u00bb<\/strong>. Des attaques qui pourraient s\u2019appuyer sur une cam\u00e9ra de vid\u00e9oprotection vuln\u00e9rable telle une Hikvision non patch\u00e9e, en tant que passerelle vers les infrastructures informatiques d\u2019un fournisseur tiers. Une m\u00e9thodologie d\u2019attaque particuli\u00e8rement pl\u00e9biscit\u00e9e et performante que nous avions pr\u00e9sent\u00e9e en d\u00e9tail lors d\u2019un <strong>article d\u00e9di\u00e9 \u00e0 la Cybers\u00e9curit\u00e9 r\u00e9dig\u00e9 en Ao\u00fbt 2019.<\/strong> \u00ab\u2009<strong><a href=\"https:\/\/www.ass-security.fr\/blog\/dossier-cybersecurite-2019-attaque-piratage-camera-videosurveillance\/\">Dossier : Attaque, Piratage &amp; cam\u00e9ras de surveillance, o\u00f9 en sommes-nous\u2009?<\/a>\u2009\u00bb<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"> News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras Hikvision | Liste non exhaustive des produits Hikvision concern\u00e9s (hors OEM)<\/h2>\n\n\n<style type=\"text\/css\">#go-pricing-table-4946 .gw-go { margin-left:-5px; } #go-pricing-table-4946 .gw-go-col { margin-left:5px; } #go-pricing-table-4946 .gw-go-col-wrap { min-width:130px; } #go-pricing-table-4946 .gw-go-col-inner { border-radius:0 0 0 0; } #go-pricing-table-4946 .gw-go-col-inner { border:none; } #go-pricing-table-4946 .gw-go-col-wrap { margin-left:0; } #go-pricing-table-4946 .gw-go-tooltip-content { background-color:#9d9d9d;color:#333333; } #go-pricing-table-4946 .gw-go-tooltip:before { border-top-color:#9d9d9d; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-header, #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-footer-row .gw-go-btn { background-color:#b06689; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-coinf div, #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-coinb div { color:#b06689; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"0\"] { font-size:14px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"1\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"2\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"3\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"4\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"5\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"6\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"7\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"8\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"9\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"10\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-0 .gw-go-body li[data-row-index=\"11\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-header, #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-footer-row .gw-go-btn { background-color:#b06689; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-coinf div, #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-coinb div { color:#b06689; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"0\"] { font-size:14px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"1\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"2\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"3\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"4\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"5\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"6\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"7\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"8\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"9\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"10\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-1 .gw-go-body li[data-row-index=\"11\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-header, #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-footer-row .gw-go-btn { background-color:#b06689; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-coinf div, #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-coinb div { color:#b06689; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"0\"] { font-size:14px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"1\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"2\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"3\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"4\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"5\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"6\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"7\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"8\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"9\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"10\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go-col-wrap-2 .gw-go-body li[data-row-index=\"11\"] { font-size:12px !important; line-height:16px !important; font-weight:bold !important; } #go-pricing-table-4946 .gw-go { visibility:inherit; }<\/style><style>@media only screen and (min-width: 480px) and (max-width: 767px) { #go-pricing-table-4946 .gw-go-col-wrap { width:50%; } }<\/style><style>@media only screen and (min-width: 480px) and (max-width: 767px) { .gw-go-tooltip { left:50% !important; right:auto !important; transform: translateX(-50%) !important; margin-left:0!important; } .gw-go-tooltip-content:before { right:auto !important; left:50% !important; margin-left:-6px !important; } }<\/style><style>@media only screen and (max-width: 479px) { #go-pricing-table-4946 .gw-go-col-wrap { width:100%; } }<\/style><style>@media only screen and (max-width: 479px) { .gw-go-tooltip { left:50% !important; right:auto !important; transform: translateX(-50%) !important; margin-left:0!important; } .gw-go-tooltip-content:before { right:auto !important; left:50% !important; margin-left:-6px !important; } }<\/style><div id=\"go-pricing-table-4946\" class=\"go-pricing\" style=\"margin-bottom:20px;\"><div class=\"gw-go gw-go-clearfix gw-go-enlarge-current gw-go-3cols\" data-id=\"4946\" data-colnum=\"3\" data-equalize=\"{&quot;column&quot;:1,&quot;body&quot;:1,&quot;footer&quot;:1}\" data-views=\"{&quot;tp&quot;:{&quot;min&quot;:&quot;768&quot;,&quot;max&quot;:&quot;959&quot;,&quot;cols&quot;:&quot;&quot;},&quot;ml&quot;:{&quot;min&quot;:&quot;480&quot;,&quot;max&quot;:&quot;767&quot;,&quot;cols&quot;:&quot;2&quot;},&quot;mp&quot;:{&quot;min&quot;:&quot;&quot;,&quot;max&quot;:&quot;479&quot;,&quot;cols&quot;:&quot;1&quot;}}\"><div class=\"gw-go-col-wrap gw-go-col-wrap-0\" data-col-index=\"0\"><div class=\"gw-go-col gw-go-clean-style2 gw-go-shadow3\"><div class=\"gw-go-col-inner\"><div class=\"gw-go-col-inner-layer\"><\/div><div class=\"gw-go-col-inner-layer-over\"><\/div><div class=\"gw-go-ribbon-left\"><img decoding=\"async\" data-src=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/plugins\/go_pricing\/assets\/images\/signs\/objects\/paperclip\/paperclip_yellow_left.png\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 30px; --smush-placeholder-aspect-ratio: 30\/72;\"><\/div><div class=\"gw-go-header\"><\/div><ul class=\"gw-go-body\"><li data-row-index=\"0\"><div class=\"gw-go-body-cell\">R\u00e9f\u00e9rences impact\u00e9es<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"1\"><div class=\"gw-go-body-cell\">DS-2CVxxx1<br>\r\nDS-2CVxxx6<\/div><\/li><li data-row-index=\"2\"><div class=\"gw-go-body-cell\">HWI-xxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"3\"><div class=\"gw-go-body-cell\">IPC-xxxx<\/div><\/li><li data-row-index=\"4\"><div class=\"gw-go-body-cell\">DS-2CD1xx1<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"5\"><div class=\"gw-go-body-cell\">DS-2CD1x23G0<br>\r\nDS-2CD1x23G0E(C)<br>\r\nDS-2CD1x43(B)<br>\r\nDS-2CD1x43(C)<br>\r\nDS-2CD1x43G0E<br>\r\nDS-2CD1x53(B)<br>\r\nDS-2CD1x53(C)<br><\/div><\/li><li data-row-index=\"6\"><div class=\"gw-go-body-cell\">DS-2CD1xx7G0<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"7\"><div class=\"gw-go-body-cell\">DS-2CD2xx6G2<br>\r\nDS-2CD2xx6G2(C)<br>\r\nDS-2CD2xx7G2<br>\r\nDS-2CD2xx7G2(C)<br><\/div><\/li><li data-row-index=\"8\"><div class=\"gw-go-body-cell\">DS-2CD2x21G0<br>\r\nDS-2CD2x21G0(C)<br>\r\nDS-2CD2x21G1<br>\r\nDS-2CD2x21G1(C)<br><\/div><\/li><li class=\"gw-go-even\" data-row-index=\"9\"><div class=\"gw-go-body-cell\">DS-2CD2xx3G2<\/div><\/li><li data-row-index=\"10\"><div class=\"gw-go-body-cell\">DS-2CD3xx6G2<br>\r\nDS-2CD3xx6G2(C)<br>\r\nDS-2CD3xx7G2<br>\r\nDS-2CD3xx7G2(C)<br><\/div><\/li><li class=\"gw-go-even\" data-row-index=\"11\"><div class=\"gw-go-body-cell\">DS-2CD3x21G0<br>\r\nDS-2CD3x21G0(C)<br>\r\nDS-2CD3x51G0(C)<br><\/div><\/li><\/ul><\/div><\/div><\/div><div class=\"gw-go-col-wrap gw-go-col-wrap-1\" data-col-index=\"1\"><div class=\"gw-go-col gw-go-clean-style2 gw-go-shadow3\"><div class=\"gw-go-col-inner\"><div class=\"gw-go-col-inner-layer\"><\/div><div class=\"gw-go-col-inner-layer-over\"><\/div><div class=\"gw-go-header\"><\/div><ul class=\"gw-go-body\"><li data-row-index=\"0\"><div class=\"gw-go-body-cell\">R\u00e9f\u00e9rences impact\u00e9es<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"1\"><div class=\"gw-go-body-cell\">DS-2CD3xx3G2<\/div><\/li><li data-row-index=\"2\"><div class=\"gw-go-body-cell\">DS-2CD4xx0<br>\r\nDS-2CD4xx6<br>\r\niDS-2XM6810<br>\r\niDS-2CD6810<br><\/div><\/li><li class=\"gw-go-even\" data-row-index=\"3\"><div class=\"gw-go-body-cell\">DS-2XE62x2F(D)<br>\r\nDS-2XC66x5G0<br>\r\nDS-2XE64x2F(B)<br><\/div><\/li><li data-row-index=\"4\"><div class=\"gw-go-body-cell\">DS-2CD8Cx6G0<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"5\"><div class=\"gw-go-body-cell\">(i)DS-2DExxxx<\/div><\/li><li data-row-index=\"6\"><div class=\"gw-go-body-cell\">(i)DS-2PTxxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"7\"><div class=\"gw-go-body-cell\">(i)DS-2SE7xxxx<\/div><\/li><li data-row-index=\"8\"><div class=\"gw-go-body-cell\">DS-2DYHxxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"9\"><div class=\"gw-go-body-cell\">DS-2DY9xxxx<\/div><\/li><li data-row-index=\"10\"><div class=\"gw-go-body-cell\">PTZ-Nxxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"11\"><div class=\"gw-go-body-cell\">HWP-Nxxxx<\/div><\/li><\/ul><\/div><\/div><\/div><div class=\"gw-go-col-wrap gw-go-col-wrap-2\" data-col-index=\"2\"><div class=\"gw-go-col gw-go-clean-style2 gw-go-shadow3\"><div class=\"gw-go-col-inner\"><div class=\"gw-go-col-inner-layer\"><\/div><div class=\"gw-go-col-inner-layer-over\"><\/div><div class=\"gw-go-header\"><\/div><ul class=\"gw-go-body\"><li data-row-index=\"0\"><div class=\"gw-go-body-cell\">R\u00e9f\u00e9rences impact\u00e9es<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"1\"><div class=\"gw-go-body-cell\">DS-2DF5xxxx<br>\r\nDS-2DF6xxxx<br>\r\nDS-2DF6xxxx-Cx<br>\r\nDS-2DF7xxxx<br>\r\nDS-2DF8xxxx<br>\r\nDS-2DF9xxxx<br><\/div><\/li><li data-row-index=\"2\"><div class=\"gw-go-body-cell\">iDS-2PT9xxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"3\"><div class=\"gw-go-body-cell\">iDS-2SR8xxxx<\/div><\/li><li data-row-index=\"4\"><div class=\"gw-go-body-cell\">iDS-2VSxxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"5\"><div class=\"gw-go-body-cell\">DS-2TBxxx<br>\r\nDS-Bxxxx<br>\r\nDS-2TDxxxxB<br><\/div><\/li><li data-row-index=\"6\"><div class=\"gw-go-body-cell\">DS-2TD1xxx-xx<br>\r\nDS-2TD2xxx-xx<br><\/div><\/li><li class=\"gw-go-even\" data-row-index=\"7\"><div class=\"gw-go-body-cell\">DS-2TD41xx-xx\/Wx<br>\r\nDS-2TD62xx-xx\/Wx<br>\r\nDS-2TD81xx-xx\/Wx<br>\r\nDS-2TD4xxx-xx\/V2<br>\r\nDS-2TD62xx-xx\/V2<br>\r\nDS-2TD81xx-xx\/V2<br><\/div><\/li><li data-row-index=\"8\"><div class=\"gw-go-body-cell\">DS-76xxNI-K1xx(C)<br>\r\nDS-76xxNI-Qxx(C)<br>\r\nDS-HiLookI-NVR-1xxMHxx-C(C)<br>\r\nDS-HiLookI-NVR-2xxMHxx-C(C)<br>\r\nDS-HiWatchI-HWN-41xxMHxx(C)<br>\r\nDS-HiWatchI-HWN-42xxMHxx(C)<br><\/div><\/li><li class=\"gw-go-even\" data-row-index=\"9\"><div class=\"gw-go-body-cell\">DS-71xxNI-Q1xx(C)<br>\r\nDS-HiLookI-NVR-1xxMHxx-D(C)<br>\r\nDS-HiLookI-NVR-1xxHxx-D(C)<br>\r\nDS-HiWatchI-HWN-21xxMHxx(C)<br>\r\nDS-HiWatchI-HWN-21xxHxx(C)<br>\r\n<\/div><\/li><li data-row-index=\"10\"><div class=\"gw-go-body-cell\">iDS-2SK7xxxx<br>\r\niDS-2SK8xxxx<\/div><\/li><li class=\"gw-go-even\" data-row-index=\"11\"><div class=\"gw-go-body-cell\">DS-2CD3xx7G0E<br>\r\n[Liste variable selon r\u00e9gion]<\/div><\/li><\/ul><\/div><\/div><\/div><\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">News : Vuln\u00e9rabilit\u00e9 critique des produits Hikvision &#8211; Faille CVE-2021-36260 | \u00c9tat des lieux en juillet 2022 par CYFIRMA<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1509\" height=\"1016\" data-src=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/rapport-hikvision-1.jpg\" alt=\"\" class=\"wp-image-5789 lazyload\" data-srcset=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/rapport-hikvision-1.jpg 1509w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/rapport-hikvision-1-768x517.jpg 768w\" data-sizes=\"auto, (max-width: 1509px) 100vw, 1509px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1509px; --smush-placeholder-aspect-ratio: 1509\/1016;\" \/><figcaption class=\"wp-element-caption\"><em>R\u00e9partition g\u00e9ographique des 80 000 cam\u00e9ras de s\u00e9curit\u00e9 Hikvision compromises  aupr\u00e8s d&rsquo;un \u00e9chantillon de 280 000 produits.<\/em><\/figcaption><\/figure>\n\n\n\n<p><strong>\u00c9crit initialement en octobre 2021<\/strong>, ce billet de blog est r\u00e9actualis\u00e9 \u00e0 ce jour <strong>(juillet 2022)<\/strong> suite \u00e0 un \u00e9tat des lieux peu \u00e9logieux dress\u00e9 par la compagnie de cybers\u00e9curit\u00e9 <strong>CYFIRMA<\/strong>, native de Singapour. Toutefois, nous tenons \u00e0 stipuler que cette faille, dont la date d\u2019anniversaire remonte \u00e0 pr\u00e8s d\u2019un an est tout sauf une r\u00e9cente \u00ab<strong> Z\u00e9ro Day<\/strong> \u00bb d\u00e9couverte quasiment sous le manteau. Il s&rsquo;agit d&rsquo;une vuln\u00e9rabilit\u00e9 connue sur le march\u00e9, enti\u00e8rement document\u00e9e quasiment livr\u00e9e cl\u00e9s en main ! Ce rapport est donc un \u00e9tat des lieux et non une d\u00e9couverte qui permet de pointer les diff\u00e9rents probl\u00e8mes que nous soulignons depuis bien longtemps sur des proc\u00e9dures de mises \u00e0 jour pas toujours simplifi\u00e9es des fabricants (<strong>Dahua et Hikvision<\/strong>) g\u00e9n\u00e9rant une pl\u00e9thore de produits de s\u00e9curit\u00e9 vuln\u00e9rables pendant des ann\u00e9es voir tout au long de leurs cycles de vie. <\/p>\n\n\n\n<p>Dans son rapport, <strong>CYFIRMA<\/strong> indique que sur un \u00e9chantillon de <strong>280\u2009000 cam\u00e9ras Hikvision<\/strong> pr\u00e9alablement sond\u00e9, pr\u00e8s de 80\u2009000 cam\u00e9ras restent vuln\u00e9rables, non patch\u00e9s soit 29% des cam\u00e9ras dans le monde\u2026 Des chiffres inqui\u00e9tants qui repr\u00e9sentent \u00e9galement la <strong>France, \u00e0 hauteur de 0,85% soit 2377 cam\u00e9ras<\/strong> concern\u00e9es sur le panel test\u00e9. Lorsqu\u2019on sait que plusieurs centaines de millions d\u2019\u00e9quipements de vid\u00e9osurveillance Hikvision sont en service dans le monde, on imagine plusieurs millions de cam\u00e9ras  compromises\u2026 Rappelons toutefois que cette faille n\u2019aura pas donn\u00e9 mati\u00e8re \u00e0 d\u00e9bats \u00e0 l\u2019\u00e9poque de sa sortie en juin 2021. Nous l\u2019avions \u00e9voqu\u00e9 parmi les premiers sur le territoire fran\u00e7ais, mais h\u00e9las sans grand impact pour ne pas dire, une certaine froideur. \u00c0 ce jour, c\u2019est <strong>BFM TV qui a relanc\u00e9 cette vuln\u00e9rabilit\u00e9<\/strong> en publiant le rapport de CYFIRMA avec, un impact m\u00e9diatique bien plus cons\u00e9quent que les blogs de passionn\u00e9s d\u2019IT ou de Cybers\u00e9curit\u00e9 que nous sommes. Soulignons toutefois qu\u2019au vu du climat g\u00e9opolitique actuel particuli\u00e8rement tendu, ce type de faille pour ne pas dire \u00ab <strong>porte ouverte<\/strong> \u00bb pourrait simplifier la donne aux attaques vers les <strong>OIV<\/strong>, <strong>organisations \u00e9tatiques<\/strong> et autres sites particuli\u00e8rement sensibles\u2026<\/p>\n\n\n\n<figure class=\"wp-block-pullquote has-medium-font-size\"><blockquote><p>\u00ab Attackers can collaborate on exploiting Hikvision cameras using the command injection #vulnerability (CVE-2021-36260) and #credential leaks that are available for sale in Russian forums on the dark web. \u00bb<\/p><cite>CYFIRMA Research (@CyfirmaR) &#8211; Aout 18, 2022 &#8211; Twitter<\/cite><\/blockquote><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision &#8211; Faille CVE-2021-36260 | Conclusion <\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"1024\" data-src=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-1024x1024.jpg\" alt=\"\" class=\"wp-image-4934 lazyload\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/1024;width:350px\" data-srcset=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-1024x1024.jpg 1024w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-500x500.jpg 500w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-150x150.jpg 150w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-768x768.jpg 768w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-1536x1536.jpg 1536w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face-2048x2048.jpg 2048w, https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2021\/09\/POPART_no_happy_face.jpg 626w\" data-sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/figure>\n<\/div>\n\n\n<p>Cette faille semble depuis le <strong>28 septembre 2021<\/strong>, quasiment corrig\u00e9e si l\u2019on se r\u00e9f\u00e8re aux diff\u00e9rents portails de mise \u00e0 jour du fabricant ou de <strong>nombreux Firmwares<\/strong> ont vu leurs dates r\u00e9actualis\u00e9es. Toutefois, force est de constater que de nombreux produits resteront dans cet \u00e9tat non patch\u00e9s par m\u00e9connaissance ou par absence de r\u00e9ponses correctives face \u00e0 la pl\u00e9thore de r\u00e9f\u00e9rences (plusieurs milliers de r\u00e9f\u00e9rences incluant les gammes OEM) couvertes par le g\u00e9ant de la vid\u00e9osurveillance <strong>d\u00e9tenu \u00e0 42% par le gouvernement chinois<\/strong>. Une campagne de rappel complexe \u00e0 mettre en \u0153uvre, surtout pour les produits n\u2019\u00e9tant plus commercialis\u00e9s. Avec un ratio peu favorable entre une <strong>criticit\u00e9 jug\u00e9e s\u00e9v\u00e8re<\/strong>, un grand nombre de produits impact\u00e9s et la m\u00e9connaissance de l\u2019existence de cette faille favorisant le hack, il sera difficile de ne pas souligner l\u2019ampleur de cette vuln\u00e9rabilit\u00e9 aux panth\u00e9ons des failles les plus marquantes de l&rsquo;histoire de la <strong><a href=\"https:\/\/www.ass-security.fr\/videosurveillance-camera\/\">vid\u00e9osurveillance<\/a><\/strong> m\u00eame si \u00e0 sa sortie en juin 2021, elle sera presque pass\u00e9 inaper\u00e7ue par un trop faible impact m\u00e9diatique l\u00e0 ou en 2017, son rival de longue date Dahua, avait quelque peu d\u00e9fray\u00e9 la chronique avec sa c\u00e9l\u00e8bre faille quasi terrorisante laissant un \u00ab HACKED \u00bb \u00e0 l&rsquo;\u00e9cran&#8230; Une vuln\u00e9rabilit\u00e9 qui vient h\u00e9las, entach\u00e9 quelque peu la r\u00e9putation d\u00e9j\u00e0 sulfureuse du fabricant chinois de cam\u00e9ras de surveillance qui, campe depuis 2019 dans le <strong>collimateur du gouvernement US en raison d&rsquo;autorisations li\u00e9 \u00e0 la \u00ab National Defense Authorization Act<\/strong> &#8211; <strong>NDAA<\/strong> \u00bb. <\/p>\n\n\n<div style=\"--icon-code: &quot;\\e958&quot;; --icon-color: #00D084; --dark-icon-color: #FFFFFF; \" class=\"list-style-element is-icon wp-block-foxiz-elements-list-style\">\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.ass-security.fr\/blog\/les-fabricants-de-videosurveillance-hikvision-et-dahua-technology-blacklistes-du-gouvernement-trump\/\"><strong>News : Hikvision &amp; Dahua blacklist\u00e9s du gouvernement Trump [\u00c9dition 1 \u2013 Nov. 2019]<\/strong><\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ass-security.fr\/blog\/hikvision-dahua-technology-blacklistes-du-gouvernement-trump-edition-2\/\"><strong>News : Hikvision &amp; Dahua blacklist\u00e9s du gouvernement Trump [\u00c9dition 2 \u2013 Avril 2020]<\/strong><\/a><\/li>\n<\/ul>\n\n<\/div>\n\n\n<p>\u00c0 savoir qu&rsquo;\u00e0 sa sortie en 2021, <strong>Watchful_IP<\/strong> n\u2019avait pas souhait\u00e9 document\u00e9 publiquement cette faille afin d\u2019\u00e9viter une vague d\u2019attaques par bon nombre d\u2019utilisateurs mal intentionn\u00e9s ou \u00ab\u2009<strong>Script Kiddie<\/strong>\u2009\u00bb et d\u2019\u00e9viter ainsi, une brute mont\u00e9e en puissance d&rsquo;attaques perp\u00e9tr\u00e9es contre les \u00e9quipements de vid\u00e9osurveillance Hikvision. Toutefois cette vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 rapidement d\u00e9mystifier par d\u2019autres chercheurs en s\u00e9curit\u00e9 tel \u00ab\u2009<strong>Bashis<\/strong>\u2009\u00bb, remontant r\u00e9guli\u00e8rement des vuln\u00e9rabilit\u00e9s \u00e9manant des cam\u00e9ras de s\u00e9curit\u00e9 <strong>Hikvision<\/strong> ou <strong>Dahua<\/strong>. Cette vuln\u00e9rabilit\u00e9 continue de laisser sur le march\u00e9 de la vid\u00e9osurveillance une certaine amertume en mati\u00e8re de cybers\u00e9curit\u00e9 avec de tr\u00e8s nombreux <strong>\u00e9quipements vuln\u00e9rables<\/strong> qui pr\u00e9sentent et pr\u00e9senteront probablement, des br\u00e8ches tout au long de leurs cycle de vie\u2026 Les dizaines de marques blanches \u00ab\u2009<strong>OEM<\/strong>\u2009\u00bb s\u2019appuyant sur des produits Hikvision risquent de ne pas proposer de correctif et bon nombre d\u2019utilisateurs ne seront gu\u00e8re au courant de la situation. Une faille qui devrait encore longtemps faire parler d\u2019elle comme nous l&rsquo;\u00e9voquions \u00e0 sa sortie en juin 2021 lors de la premi\u00e8re version de cette article. On esp\u00e8re comme chaque ann\u00e9e lors de nos v\u0153ux (!) une am\u00e9lioration globale de la <strong>s\u00e9curit\u00e9 intrins\u00e8que de l&rsquo;IoT<\/strong> et plus principalement des cam\u00e9ras de vid\u00e9osurveillance toutes marques confondues..<\/p>\n\n\n<div style=\"--icon-code: &quot;\\e958&quot;; --icon-color: #00D084; --dark-icon-color: #FFFFFF; \" class=\"list-style-element is-icon wp-block-foxiz-elements-list-style\">\n\n<ul class=\"wp-block-list\">\n<li><strong>Bulletin de vuln\u00e9rabilit\u00e9 par @Watchout_IP : https:\/\/watchfulip.github.io<\/strong><\/li>\n\n\n\n<li><strong>Rapport Cyfirma : <a href=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/ass-security-HikvisionSurveillanceCamerasVulnerabilities.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">T\u00e9l\u00e9charger le rapport CYFIRMA\/HIKVISION (Format PDF)<\/a><\/strong><\/li>\n<\/ul>\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Une faille RCE &#8211; Remote Code Execution affecte la plupart des cam\u00e9ras de surveillance Hikvision construite \u00e0 partir de 2016 jusqu\u2019\u00e0 aujourd\u2019hui (hors cam\u00e9ras patch\u00e9es apr\u00e8s septembre 2021). Les failles RCE sont des vuln\u00e9rabilit\u00e9s de s\u00e9curit\u00e9 logicielle permettant l\u2019ex\u00e9cution d\u2019un code malveillant en local ou \u00e0 distance vers l\u2019\u00e9quipement concern\u00e9. Une faille laissant envisager une [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5782,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[506,17],"tags":[379,302,61,181,60,223],"class_list":{"0":"post-4883","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cybersecurite","8":"category-news","9":"tag-camera-2","10":"tag-cybersecurite","11":"tag-hikvision","12":"tag-ip-camera","13":"tag-onvif","14":"tag-securite"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>News : Faille de s\u00e9curit\u00e9\/vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision<\/title>\n<meta name=\"description\" content=\"News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision - Faille de s\u00e9curit\u00e9 CVE-2021-36260 | Installateur Alarme Nantes - Loire-Atlantique\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"News : Faille de s\u00e9curit\u00e9\/vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision\" \/>\n<meta property=\"og:description\" content=\"News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision - Faille de s\u00e9curit\u00e9 CVE-2021-36260 | Installateur Alarme Nantes - Loire-Atlantique\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/\" \/>\n<meta property=\"og:site_name\" content=\"ASS Security Blog : Dossiers \/ Tests \/ News sur les alarmes et les syst\u00e8mes de s\u00e9curit\u00e9\" \/>\n<meta property=\"article:published_time\" content=\"2022-08-29T22:11:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-16T17:47:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"530\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Axel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Axel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/\"},\"author\":{\"name\":\"Axel\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/#\\\/schema\\\/person\\\/846856e1470e7e879fcbff088c2dd2c0\"},\"headline\":\"News : Vuln\u00e9rabilit\u00e9 critique not\u00e9e par le CVSS 9,8 pour les cam\u00e9ras de vid\u00e9osurveillance Hikvision &#8211; Faille CVE-2021-36260\",\"datePublished\":\"2022-08-29T22:11:33+00:00\",\"dateModified\":\"2025-02-16T17:47:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/\"},\"wordCount\":1767,\"commentCount\":4,\"image\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg\",\"keywords\":[\"CAMERA\",\"CyberS\u00e9curit\u00e9\",\"Hikvision\",\"IP Camera\",\"ONVIF\",\"Securit\u00e9\"],\"articleSection\":[\"Cybers\u00e9curit\u00e9\",\"News\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/\",\"url\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/\",\"name\":\"News : Faille de s\u00e9curit\u00e9\\\/vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg\",\"datePublished\":\"2022-08-29T22:11:33+00:00\",\"dateModified\":\"2025-02-16T17:47:53+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/#\\\/schema\\\/person\\\/846856e1470e7e879fcbff088c2dd2c0\"},\"description\":\"News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision - Faille de s\u00e9curit\u00e9 CVE-2021-36260 | Installateur Alarme Nantes - Loire-Atlantique\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg\",\"width\":1000,\"height\":530},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"News : Vuln\u00e9rabilit\u00e9 critique not\u00e9e par le CVSS 9,8 pour les cam\u00e9ras de vid\u00e9osurveillance Hikvision &#8211; Faille CVE-2021-36260\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/\",\"name\":\"ASS Security Blog : Dossiers \\\/ Tests \\\/ News sur les alarmes et les syst\u00e8mes de s\u00e9curit\u00e9\",\"description\":\"Actualit\u00e9s sur les syst\u00e8mes d&#039;alarmes, tests, dossiers vid\u00e9osurveillance, Cybers\u00e9curit\u00e9 | Blog alarme | Installateur Alarme Nantes\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/#\\\/schema\\\/person\\\/846856e1470e7e879fcbff088c2dd2c0\",\"name\":\"Axel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/da2947c63bee11cc33eb6c698e50ac20dc3ca54aad9120ddc0169e845e91c8e0?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/da2947c63bee11cc33eb6c698e50ac20dc3ca54aad9120ddc0169e845e91c8e0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/da2947c63bee11cc33eb6c698e50ac20dc3ca54aad9120ddc0169e845e91c8e0?s=96&d=mm&r=g\",\"caption\":\"Axel\"},\"description\":\"F\u00e9ru des nouvelles technologies, tout en poss\u00e9dant une fibre \\\"RetroGeek\\\" je suis sp\u00e9cialiste depuis plus de 15 ans dans le domaine de la suret\u00e9 \u00e9lectronique. Autodidacte et perfectionniste avec moi-m\u00eame, mon m\u00e9tier, au contact des hommes &amp; des machines est la source de mes inspirations.\",\"sameAs\":[\"www.linkedin.com\\\/in\\\/axeljacq\\\/\"],\"url\":\"https:\\\/\\\/www.ass-security.fr\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"News : Faille de s\u00e9curit\u00e9\/vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision","description":"News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision - Faille de s\u00e9curit\u00e9 CVE-2021-36260 | Installateur Alarme Nantes - Loire-Atlantique","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/","og_locale":"fr_FR","og_type":"article","og_title":"News : Faille de s\u00e9curit\u00e9\/vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision","og_description":"News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision - Faille de s\u00e9curit\u00e9 CVE-2021-36260 | Installateur Alarme Nantes - Loire-Atlantique","og_url":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/","og_site_name":"ASS Security Blog : Dossiers \/ Tests \/ News sur les alarmes et les syst\u00e8mes de s\u00e9curit\u00e9","article_published_time":"2022-08-29T22:11:33+00:00","article_modified_time":"2025-02-16T17:47:53+00:00","og_image":[{"width":1000,"height":530,"url":"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg","type":"image\/jpeg"}],"author":"Axel","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Axel","Dur\u00e9e de lecture estim\u00e9e":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#article","isPartOf":{"@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/"},"author":{"name":"Axel","@id":"https:\/\/www.ass-security.fr\/blog\/#\/schema\/person\/846856e1470e7e879fcbff088c2dd2c0"},"headline":"News : Vuln\u00e9rabilit\u00e9 critique not\u00e9e par le CVSS 9,8 pour les cam\u00e9ras de vid\u00e9osurveillance Hikvision &#8211; Faille CVE-2021-36260","datePublished":"2022-08-29T22:11:33+00:00","dateModified":"2025-02-16T17:47:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/"},"wordCount":1767,"commentCount":4,"image":{"@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg","keywords":["CAMERA","CyberS\u00e9curit\u00e9","Hikvision","IP Camera","ONVIF","Securit\u00e9"],"articleSection":["Cybers\u00e9curit\u00e9","News"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/","url":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/","name":"News : Faille de s\u00e9curit\u00e9\/vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision","isPartOf":{"@id":"https:\/\/www.ass-security.fr\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#primaryimage"},"image":{"@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg","datePublished":"2022-08-29T22:11:33+00:00","dateModified":"2025-02-16T17:47:53+00:00","author":{"@id":"https:\/\/www.ass-security.fr\/blog\/#\/schema\/person\/846856e1470e7e879fcbff088c2dd2c0"},"description":"News : Vuln\u00e9rabilit\u00e9 critique pour les cam\u00e9ras et enregistreurs Hikvision - Faille de s\u00e9curit\u00e9 CVE-2021-36260 | Installateur Alarme Nantes - Loire-Atlantique","breadcrumb":{"@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#primaryimage","url":"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg","contentUrl":"https:\/\/www.ass-security.fr\/blog\/wp-content\/uploads\/2022\/08\/HIKVISION-CRITICAL-vulnerabilitie_NANTES_ASS-SECURITY-.2jpg.jpg","width":1000,"height":530},{"@type":"BreadcrumbList","@id":"https:\/\/www.ass-security.fr\/blog\/vulnerabilite-critique-pour-les-cameras-hikvision-faille-cve-2021-36260\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.ass-security.fr\/blog\/"},{"@type":"ListItem","position":2,"name":"News : Vuln\u00e9rabilit\u00e9 critique not\u00e9e par le CVSS 9,8 pour les cam\u00e9ras de vid\u00e9osurveillance Hikvision &#8211; Faille CVE-2021-36260"}]},{"@type":"WebSite","@id":"https:\/\/www.ass-security.fr\/blog\/#website","url":"https:\/\/www.ass-security.fr\/blog\/","name":"ASS Security Blog : Dossiers \/ Tests \/ News sur les alarmes et les syst\u00e8mes de s\u00e9curit\u00e9","description":"Actualit\u00e9s sur les syst\u00e8mes d&#039;alarmes, tests, dossiers vid\u00e9osurveillance, Cybers\u00e9curit\u00e9 | Blog alarme | Installateur Alarme Nantes","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ass-security.fr\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/www.ass-security.fr\/blog\/#\/schema\/person\/846856e1470e7e879fcbff088c2dd2c0","name":"Axel","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/da2947c63bee11cc33eb6c698e50ac20dc3ca54aad9120ddc0169e845e91c8e0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/da2947c63bee11cc33eb6c698e50ac20dc3ca54aad9120ddc0169e845e91c8e0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/da2947c63bee11cc33eb6c698e50ac20dc3ca54aad9120ddc0169e845e91c8e0?s=96&d=mm&r=g","caption":"Axel"},"description":"F\u00e9ru des nouvelles technologies, tout en poss\u00e9dant une fibre \"RetroGeek\" je suis sp\u00e9cialiste depuis plus de 15 ans dans le domaine de la suret\u00e9 \u00e9lectronique. Autodidacte et perfectionniste avec moi-m\u00eame, mon m\u00e9tier, au contact des hommes &amp; des machines est la source de mes inspirations.","sameAs":["www.linkedin.com\/in\/axeljacq\/"],"url":"https:\/\/www.ass-security.fr\/blog\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/posts\/4883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/comments?post=4883"}],"version-history":[{"count":0,"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/posts\/4883\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/media\/5782"}],"wp:attachment":[{"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/media?parent=4883"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/categories?post=4883"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ass-security.fr\/blog\/wp-json\/wp\/v2\/tags?post=4883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}