Imou Device Vulnerability Disclosure V1.0

2024-03-22

Imou Device Vulnerability Disclosure V1.0

1、 Vulnerability report:

You can send an email to security@imou.com to report the vulnerabilities you have discovered. For the convenience of verifying and locating vulnerabilities, please try to include but not limited to the following content in the report:

1. Organizational structure/address and contact information.

2. Description of potential security risks/vulnerabilities.

3. Technical details (such as system configuration, localization methods, description/screenshot of Explorit, sample packet capture, PoC, problem reproduction steps, etc.).

4. Report the product, model, software/firmware version where the security risk/vulnerability is located.

5. Possible vulnerability disclosure plan.

 

2、 Vulnerability classification and processing time:

Vulnerability classification: According to the degree of vulnerability harm, it is divided into three levels: high risk, medium risk, and low risk. Each level is evaluated as follows:

Vulnerability types Specific segmentation Grading
Exceeding authority and remote command execution Execution of ordinary ultra vires or partial orders low risk
Implement control over a single device or within a local area network medium risk
Remote control of a single device or batch control of devices outside the local area network high risk
Information leakage The leaked content will not cause a security incident, but there are indeed security risks or defects low risk
The leaked content can cause small-scale security incidents medium risk
The leaked content can cause large-scale security incidents high risk
Denial of service Denial of service for a single device that has a serious impact on the device low risk
Denial of service that can be utilized on a small scale medium risk
Denial of service that can cause widespread device paralysis high risk

Processing time:

1. Within one working day, the staff of Imou Security Center will confirm receipt of the vulnerability report and follow up to evaluate the issue.

2. Within 3 working days, the staff of Imou Safety Center will handle the issue and provide a conclusion. If necessary, we will communicate and confirm with the submitter, and request assistance.

3. The business department fixes vulnerabilities, and the repair time depends on the severity and difficulty of the problem. Severe and high-risk vulnerabilities are fixed within 48 hours, medium risk vulnerabilities are fixed within 3 working days, and low risk vulnerabilities are fixed within 7 working days. Some vulnerabilities are subject to version release restrictions, and the repair time will be determined based on the actual situation. Serious or significant impact vulnerabilities will be subject to separate emergency security announcements.

 

3、Vulnerability handling process:

1. Received: You can send an email to security@imou.com to report the vulnerabilities you have discovered.

2. Verification: Within one working day, Imou security personnel will confirm receipt of the vulnerability report and follow up to evaluate the issue. Security personnel will address the issue and provide a conclusion within 3 working days. If necessary, we will communicate and confirm with the submitter and request assistance.

3. Fix: The business department fixes vulnerabilities, and the repair time depends on the severity and difficulty of the problem. Severe and high-risk vulnerabilities are fixed within 48 hours, medium risk vulnerabilities are fixed within 3 working days, and low-risk vulnerabilities are fixed within 7 working days.

4. Disclosure: Some vulnerabilities are subject to version release restrictions, and the repair time will be determined based on the actual situation. Serious or significant impact vulnerabilities will be subject to separate emergency security announcements.

5. Improvement: Inspection and maintenance of all products.

 

4、 Sustainable renewal cycle:

We make every effort to provide continuous security updates for our products. Security updates typically include the latest security patches, security vulnerability fixes, and other security improvements. We will maintain security updates for at least 2 years after the first release of the product model.

 

5、 Device password modification instructions:

1. Log in to the Imou Life app.

2. Enter the device settings tab where the password needs to be changed.

3. After clicking on the device name tab, click on the device password.

4. In the pop-up modification tab, enter the old password once and the new password twice, and then click save below.