EXECUTIVE SUMMARY
A newly discovered command injection vulnerability in AVTECH IP camera devices allows for remote code execution (RCE) and is being actively exploited in the wild. This vulnerability, found in the brightness function of the devices, has become a focal point for a botnet campaign spreading a variant of the Mirai malware. This botnet leverages both the new vulnerability and several older, unpatched vulnerabilities to infect and control target systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A newly discovered command injection vulnerability in AVTECH IP camera devices allows for remote code execution (RCE) and is being actively exploited in the wild. This vulnerability, found in the brightness function of the devices, has become a focal point for a botnet campaign spreading a variant of the Mirai malware. This botnet leverages both the new vulnerability and several older, unpatched vulnerabilities to infect and control target systems.[emaillocker id="1283"]
The zero-day vulnerability, identified as CVE-2024-7029, is a command injection flaw within the brightness function of AVTECH CCTV cameras. This vulnerability enables remote code execution (RCE) through the injection of malicious commands. The affected devices are those running specific AVTECH firmware versions. Despite the discontinuation of these models, they are still in use globally, particularly within critical infrastructure. Exploiting this vulnerability allows attackers to execute commands with elevated privileges, facilitating the spread of the Mirai variant. The botnet campaign also targets other known vulnerabilities, including a Hadoop YARN RCE, CVE-2014-8361, and CVE-2017-17215. These older vulnerabilities remain unpatched in many systems, enabling their ongoing exploitation by the botnet.
This botnet campaign highlights the growing trend of exploiting both new and under-the-radar vulnerabilities in legacy systems, posing significant risks to organizations that rely on outdated hardware and software. Given the lack of patches for some of these vulnerabilities, organizations should prioritize patch management where possible and consider decommissioning vulnerable devices to mitigate security risks. The campaign underscores the importance of proactive threat monitoring and timely vulnerability management in safeguarding critical infrastructure.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| T1203 | Exploitation for Client Execution | |
| Defense Evasion | T1078 | Valid Accounts |
| T1027 | Obfuscated Files or Information | |
| Collection | T1074 | Data Staged |
| Command and Control | T1071 | Application Layer Protocol |
| Impact | T1498 | Network Denial of Service |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/malware-exploits-5-year-old-zero-day-to-infect-end-of-life-ip-cameras/