We use cookies to improve user experience. By using this website you agree to the placement of cookies. More information on our Cookie Policy .

OK
< Faq Lists

FAQ

DIGIEVER Cybersecurity Update Notice

 

Overview

DIGIEVER is committed to providing secure and reliable Linux-embedded video surveillance solutions, ensuring that data and devices are protected from cyber threats. Whenever potential security vulnerabilities are identified or reported, we take immediate action to address them and enhance device security. This report outlines the latest security fixes and general recommendations to help customers maintain the safety of their devices.


We encourage all customers to update their firmware promptly, follow the security recommendations below, and contact our technical support team (support@digiever.com) for further assistance. DIGIEVER is committed to providing secure and reliable surveillance solutions, and we thank you for your trust and support.


Security Enhancement Recommendation

To further safeguard DIGIEVER products, we recommend adopting the following measures:
Network Security:
        o Isolate the device from the internet by using a firewall or whitelist to restrict external access. For remote management, consider using a VPN for secure access.
        o Segment the NVR from other networks to minimize potential risks.


Authentication and Access Control: Immediately change the default username and password of the device, using a strong password (at least 12 characters, including letters, numbers, and symbols), and update it regularly.


Firmware and Software Updates: Regularly check for and install the latest firmware to apply security patches. For devices older than 10 years, please contact us (support@digiever.com).


Monitoring and Log Management: Periodically review log records to identify any abnormal access or unauthorized attempts.

 

Risk and Impact Assessment

Vulnerability Impact: Unpatched devices may be susceptible to malware infections, potentially leading to data breaches or the device being exploited for cyberattacks.


Post-Fix Risks: After applying the fix, the primary vulnerabilities are resolved. However, if the device remains exposed to the internet or credentials are not updated, other security risks may persist.


Customer Impact: Customers who have not updated their firmware should take immediate action, while those who have updated should continue monitoring their devices.


Cybersecurity and Compliance History

We regularly address potential security issues identified in our products, which may affect various models, particularly those not updated to the latest firmware. Below is the latest fix information:
• Fix Measures: We have released a new firmware update, which addresses the relevant security vulnerabilities. The update has undergone internal testing and third-party verification to ensure the issues are resolved. Customers can download and apply the latest firmware from the DIGIEVER official website.

Version Topic Severity Impact Solved Method CVE Record
FW78-7

Improve API security:

① time_tzsetup.cgi
② access_device.cgi

Important ① NVR stops recording due to the error of NTP process.
② Outsider may get NVR setting information
① Forbid invalid commands to avoid other possible accesses via other DDoS methods
② Only access control's name can be retrieved with this command
① CVE-2023- 52163
② CVE-2023- 52164