Axis Communications Vulnerability Exposes Azure Storage Account Credentials
A critical vulnerability in the Autodesk Revit plugin by Axis Communications has exposed Azure Storage Account credentials, posing significant security risks for users and creating potential for supply chain attacks within the architecture and…
A critical vulnerability in the Autodesk Revit plugin by Axis Communications has exposed Azure Storage Account credentials, posing significant security risks for users and creating potential for supply chain attacks within the architecture and engineering sectors.
The vulnerability arises from hardcoded credentials within signed Dynamic Link Libraries (DLLs) distributed via the plugin’s Microsoft Installer (MSI) package.
The issue was identified in July 2024 when Trend Micro's VirusTotal rules detected Azure Shared Access Signature (SAS) tokens in a digitally signed DLL named "AzureBlobRestAPI.dll."
The affected component was provided to AEC Advanced Engineering Computation Aktiebolag, an Autodesk partner specializing in consulting for AutoCAD and Revit platforms.
The exposed credentials allowed unauthorized read and write access to three Azure storage accounts belonging to Axis Communications, a company specializing in network video solutions and surveillance technology.
The vulnerability is rooted in inadequate credential management within the plugin’s architecture.
The vulnerability is rooted in inadequate credential management within the plugin’s architecture. Researchers discovered cleartext Azure SAS tokens and shared access key pairs for two Azure storage accounts, "axisfiles" and "axiscontentfiles," within a private method called "internalSetEnvironment" of the class "AzureBlobRestAPI.DataTypes.Classes.Global."
These credentials provided extensive privileges, including read, write, delete, list, add, create, update, process, and execute permissions across the storage accounts.
Axis Communications initially attempted remediation in version 25.3.710 through code obfuscation using tools like Eazfuscator. However, this was inadequate as the obfuscated credentials could be de-obfuscated using publicly available tools.
The vulnerability persisted due to historical plugin versions containing overly permissive credentials. Full remediation was achieved in version 25.3.718, with Axis Communications confirming all issues have been addressed.
Axis Communications has taken steps to notify affected partners and customers. The Autodesk Revit plugin is available only to select partners, not for public distribution.
Based on reporting by Cyber Security News.
