Guardzilla IoT Surveillance Bypass Vulnerability
Security researchers have disclosed details of a password bypass vulnerability in Guardzilla's All-In-One Video Security System products.
Summary
Security researchers have disclosed details of a password bypass vulnerability in Guardzilla's All-In-One Video Security System products.
Affected platforms
The following platforms are known to be affected:
Threat details
They claim an unauthenticated remote attacker could exploit this vulnerability to gain access to the video files of all Guardzilla users.
Guardzilla All-In-One devices use a single set of hard-coded Amazon S3 credentials used for storing saved video files. The researchers discovered that these credentials provide full access to the stored files, including those of other users, as well as to Guardzilla's motion detection and recognition modules, and can be easily obtained from any affected device.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Users and administrators should visit Guardzilla's support pages for guidance on their affected products. |
Last edited: 14 February 2020 2:53 pm