A significant vulnerability has been identified in a widely used open-source software library, posing a substantial risk to millions of Internet of Things (IoT) devices. Known as CVE-2017-9765, this flaw was uncovered by security experts at the IoT-focused firm Senrio and affects the gSOAP toolkit, which is instrumental in developing XML Web services.
Referred to as “Devil’s Ivy,” this critical stack buffer overflow vulnerability allows remote attackers not only to crash affected devices but also to execute arbitrary code, potentially compromising systems indiscriminately. Senrio’s research notably focused on an Internet-connected security camera produced by Axis Communications, leading to alarming findings regarding the device’s security posture.
When successfully exploited, the vulnerability enables attackers to gain unauthorized access to video feeds from the cameras, which could have dire implications, particularly in environments intended for security, such as banks. Sensitive information could be captured, or critical incidents could go unnoticed, enhancing the urgency for affected users to implement countermeasures.
Axis Communications confirmed that nearly all of its 250 camera models are susceptible to this vulnerability, and promptly issued firmware updates on July 6 to address the issue, urging users to upgrade to the patched versions without delay. The company also communicated the flaw to Genivia, the maintainer of gSOAP, who had already released a patch by June 21, 2017.
Moreover, Axis proactively alerted the electronics consortium ONVIF to ensure that its members—including other major manufacturers like Canon, Siemens, and Cisco—are aware of the vulnerability and can develop fixes for their devices as necessary. This indicates a clear recognition within the industry of the expansive impact that such vulnerabilities can have across various platforms and products.
Given the interconnected nature of IoT devices and the reliance on commonly used software libraries, the risk extends beyond Axis products to those from other manufacturers. Business owners with IoT systems must be vigilant, as vulnerabilities in these devices can serve as gateways for hackers to gain access to enterprise networks, potentially falling under the MITRE ATT&CK tactics of initial access and privilege escalation.
It’s important for organizations to maintain updated software and security protocols for all internet-connected devices. IoT devices have long been considered a weak point because of their ease of exploitation, underscoring the necessity of heightened scrutiny and robust defensive strategies to protect against such pervasive threats.
In light of these developments, business owners are advised to follow industry news and stay informed about emerging vulnerabilities that could impact their operations. Being proactive in addressing such security concerns is essential to safeguarding valuable data and maintaining secure networks in an increasingly digital landscape.