Brickcom Cameras
This CISA advisory details a critical vulnerability in Brickcom cameras (Cube, Dome, Bullet, and Box models, version 3.2.3.5.6) that allows unauthenticated remote attackers to access live video feeds and retrieve sensitive visual information. The vulnerability stems from the use of default credentials and the lack of authentication on the /ONVIF endpoint. The advisory urges users to mitigate the risk by minimizing network exposure and implementing secure remote access methods.
The vulnerability discovered by CISA, demonstrated through proof-of-concept code authored by parsa rezaie khiabanloo, allows attackers to bypass security measures and gain unauthorized access to Brickcom camera feeds. The affected cameras ship with default credentials, making them susceptible to exploitation by anyone who knows the IP address. This poses a significant risk to organizations utilizing these cameras, particularly those in critical infrastructure sectors like Commercial Facilities, Critical Manufacturing, Financial Services, Healthcare and Public Health, which are targeted by this vulnerability. CISA recommends immediate action to reduce the attack surface.