Flaw in Camera Client Service from Hanwha Vision Lacks Certificate Validation
CVE-2025-52598
6.3MEDIUM
What is CVE-2025-52598?
A significant vulnerability has been identified in the camera client service provided by Hanwha Vision, wherein the service fails to properly validate digital certificates. This could potentially expose users to various risks as unauthorized entities may exploit this flaw to intercept communications or impersonate legitimate devices, ultimately compromising the security of Industrial Control Systems (ICS) and Operational Technology (OT) environments. Users are urged to refer to the manufacturer's report for details on the firmware patch which addresses this issue, along with suggested workarounds to mitigate potential risks.
Affected Version(s)
QNV-C8012 Prior to version 2.22.05
