KEEP-IT-SECURE-24

Home Case Studies Hacking a Smart Camera: Exposures & Vulnerabilities

Hacking a Smart Camera: Exposures & Vulnerabilities

Case Study Download (PDF)

The Snapshot

1

In-depth security testing of a Smart Camera across physical, network, and API threat vectors.

2

Multiple critical vulnerabilities discovered and resolved, including access to video footage and backend infrastructure compromise.

3

Client engaged the KEEP-IT-SECURE-24 service to ensure continuous security monitoring of other solutions.

The Client

A leading performance analysis company operating in a global geography, introducing the latest technologies in its industry to achieve insightful data from camera real time video streaming.

The Challenge

As an industry leader, the client strives to introduce the latest technologies in its industry in order to achieve insightful data from camera real time video streaming. The process used to capture video and execute analysis relies on the geographical distribution of cameras that sometimes might not be connected to trusted environments.

The client asked Devoteam Cyber Trust to subject their star product, a Smart Camera, to in-depth security testing.

The Solution

A Pentest project was conducted considering multiple threat vectors:

Physical access – Cameras placed in unsecure areas; potential attacker can access them to gather knowledge or compromise the system.
Wired and Wireless network access – Cameras in unsecured networks that can be accessed by potential attackers.
API endpoints – Directly consumed by the camera on the client infrastructure were also targeted.

Techniques included hardware research, boot subversion, Wi-Fi enrolment tests, SSD extraction, Ethernet interception, alternative OS boot via Micro SD-Card, and MiTM via CA installation.

The Impact

The Pentest project helped the client to understand the risks that the solution posed and enabled the resolution of vulnerabilities, preventing them from being used by real attackers to impact the organisation or solution users.

Confronted with the detailed results, the client perceived the value of continuous security monitoring and engaged with the KEEP-IT-SECURE-24 Service for several other solutions.

Related Services

Back to Case Studies

Your Security
Starts Here

Partner with Devoteam Cyber Trust to gain expert-led cybersecurity assessments and a culture of continuous risk improvement.

→ Get in touch

Contact us.

Headquarters

Torre Fernão de Magalhães
Avenida D. João II, nº 43, 9º Piso, Parque das Nações
1990-084, Lisboa | Portugal
T: +351 21 33 03 740
E: info@integrity.pt

And we are present in 18 more countries across EMEA.
world map
 




Cookie Consent X

Devoteam Cyber Trust S.A. uses cookies for analytical and more personalized information presentation purposes, based on your browsing habits and profile. For more detailed information, see our Cookie Policy.