{"id":59506,"date":"2024-09-06T19:39:46","date_gmt":"2024-09-06T16:39:46","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/181384\/SYSS-2024-029.txt"},"modified":"2024-09-06T19:39:46","modified_gmt":"2024-09-06T16:39:46","slug":"c-mor-video-surveillance-5-2401-insecure-third-party-components","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/c-mor-video-surveillance-5-2401-insecure-third-party-components\/","title":{"rendered":"C-MOR Video Surveillance 5.2401 Insecure Third-Party Components"},"content":{"rendered":"<p>Advisory ID: SYSS-2024-029<br \/>Product: C-MOR Video Surveillance<br \/>Manufacturer: za-internet GmbH<br \/>Affected Version(s): 5.2401<br \/>Tested Version(s): 5.2401<br \/>Vulnerability Type: Dependency on Vulnerable Third-Party <br \/>Component (CWE-1395)<br \/>Use of Unmaintained Third Party Components <br \/>(CWE-1104)<br \/>Risk Level: High<br \/>Solution Status: Fixed<br \/>Manufacturer Notification: 2024-04-05<br \/>Solution Date: 2024-07-31<br \/>Public Disclosure: 2024-09-04<br \/>CVE Reference: CVE-2017-9798, CVE-2017-3167, and more<br \/>Authors of Advisory: Chris Beiter, Frederik Beimgraben,<br \/>and Matthias Deeg<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Overview:<\/p>\n<p>The software product C-MOR is an IP video surveillance system.<\/p>\n<p>The manufacturer describes the product as follows:<\/p>\n<p>&#8220;With C-MOR video surveillance, it is possible to check your<br \/>surveillance over network and the Internet. You can access the live<br \/>view as well as previous recordings from any PC or mobile device.<br \/>C-MOR is managed and controlled over the C-MOR web interface.<br \/>IP settings, camera recording setup, user rights and so on are set<br \/>over the web without the installation of any software on the<br \/>client.&#8221;[1]<\/p>\n<p>The C-MOR system uses several outdated third-party software components<br \/>with known security vulnerabilities.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Vulnerability Details:<\/p>\n<p>By analyzing the C-MOR system, it was found that the C-MOR system depends<br \/>on several outdated third-party software components with known security<br \/>vulnerabilities, for instance an old Linux kernel, Apache HTTP Server<br \/>2.2.16, PHP 5.3.3, or Python 2.6.<\/p>\n<p>Some of the used software components have also reached their end of life<br \/>and are not supported anymore by a maintainer.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Proof of Concept (PoC):<\/p>\n<p>The following excerpt of the &#8220;dpkg-query&#8221; output illustrates some outdated<br \/>third-party software components used on the C-MOR system:<\/p>\n<p>$ sudo dpkg-query -l<br \/>(&#8230;)<br \/>ii apache2 2.2.16-6+squeeze10 <br \/>Apache HTTP Server metapackage<br \/>ii apache2-mpm-prefork 2.2.16-6+squeeze10 <br \/>Apache HTTP Server &#8211; traditional non-threaded model<br \/>ii apache2-utils 2.2.16-6+squeeze10 <br \/>utility programs for webservers<br \/>ii apache2.2-bin 2.2.16-6+squeeze10 <br \/>Apache HTTP Server common binary files<br \/>ii apache2.2-common 2.2.16-6+squeeze10 <br \/>Apache HTTP Server common files<br \/>(&#8230;)<br \/>ii libapache2-mod-php5 5.3.3-7+squeeze14 <br \/>server-side, HTML-embedded scripting language (Apache 2 module)<br \/>(&#8230;)<br \/>ii libssl0.9.8 0.9.8o-4squeeze14 SSL <br \/>shared libraries<br \/>(&#8230;)<br \/>ii linux-image-4.7.8 c-mor-v5-00 <br \/>Linux kernel binary image for version 4.7.8<br \/>(&#8230;)<br \/>ii php5 5.3.3-7+squeeze14 <br \/>server-side, HTML-embedded scripting language (metapackage)<br \/>rc php5-cgi 5.3.3-7+squeeze14 <br \/>server-side, HTML-embedded scripting language (CGI binary)<br \/>ii php5-cli 5.3.3-7+squeeze14 <br \/>command-line interpreter for the php5 scripting language<br \/>ii php5-common 5.3.3-7+squeeze14 <br \/>Common files for packages built from the php5 source<br \/>ii php5-gd 5.3.3-7+squeeze14 GD <br \/>module for php5<br \/>ii php5-mysql 5.3.3-7+squeeze14 <br \/>MySQL module for php5<br \/>ii php5-suhosin 0.9.32.1-1 <br \/>advanced protection module for php5<br \/>(&#8230;)<br \/>ii python2.6 2.6.6-8+b1 An <br \/>interactive high-level object-oriented language (version 2.6)<br \/>ii python2.6-minimal 2.6.6-8+b1 A <br \/>minimal subset of the Python language (version 2.6)<br \/>(&#8230;)<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Solution:<\/p>\n<p>Install C-MOR Video Surveillance version 6.00PL1.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Disclosure Timeline:<\/p>\n<p>2024-04-05: Vulnerability reported to manufacturer<br \/>2024-04-05: Manufacturer acknowledges receipt of security advisories<br \/>2024-04-08: Exchange regarding security updates and disclosure timeline<br \/>2024-05-08: Further exchange concerning security updates and disclosure<br \/>timeline; public release of all security advisories<br \/>scheduled for release of C-MOR Video Surveillance version 6<br \/>2024-05-10: Release of C-MOR software version 5.30 with security updates<br \/>for some reported security issues<br \/>2024-07-19: E-mail to manufacturer concerning release date of C-MOR<br \/>Video Surveillance version 6; response with planned<br \/>release date of 2024-08-01<br \/>2024-07-30: E-mail from manufacturer with further information<br \/>concerning security fixes<br \/>2024-07-31: Release of C-MOR software version 6.00PL1<br \/>2024-09-04: Public release of security advisory<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>References:<\/p>\n<p>[1] Product website for C-MOR Video Surveillance<br \/>https:\/\/www.c-mor.com\/<br \/>[2] SySS Security Advisory SYSS-2024-029<\/p>\n<p>https:\/\/www.syss.de\/fileadmin\/dokumente\/Publikationen\/Advisories\/SYSS-2024-029.txt<br \/>[3] SySS Responsible Disclosure Policy<br \/>https:\/\/www.syss.de\/en\/responsible-disclosure-policy\/<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Credits:<\/p>\n<p>This security vulnerability was found by Chris Beiter, and Frederik<br \/>Beimgraben.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Disclaimer:<\/p>\n<p>The information provided in this security advisory is provided &#8220;as is&#8221;<br \/>and without warranty of any kind. Details of this security advisory may<br \/>be updated in order to provide as accurate information as possible. The<br \/>latest version of this security advisory is available on the SySS Web<br \/>site.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Copyright:<\/p>\n<p>Creative Commons &#8211; Attribution (by) &#8211; Version 3.0<br \/>URL: http:\/\/creativecommons.org\/licenses\/by\/3.0\/deed.en<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Advisory ID: SYSS-2024-029Product: C-MOR Video SurveillanceManufacturer: za-internet GmbHAffected Version(s): 5.2401Tested Version(s): 5.2401Vulnerability Type: Dependency on Vulnerable Third-Party Component (CWE-1395)Use of Unmaintained Third Party Components (CWE-1104)Risk Level: HighSolution Status: FixedManufacturer Notification: 2024-04-05Solution Date: 2024-07-31Public Disclosure: 2024-09-04CVE Reference: CVE-2017-9798, CVE-2017-3167, and moreAuthors of Advisory: Chris Beiter, Frederik Beimgraben,and Matthias Deeg ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: The software product C-MOR is &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59506","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59506"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59506\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}