Skip to main content

Backdoors found in AMX audio-visual equipment sold to government

AMX, a company that produces audio and visual (AV) control systems designed for conferencing, has been accused of installing a deliberate backdoor in a number of its products, that makes it possible to set up an admin account that can sniff the local network, without prior privileges. Although it denies it, AMX appeared to update software in an attempt to obfuscate the flaw in its security, rather than fix it.

The flaw was originally picked up by Austrian digital security firm, SEC Consult, last year when it discovered the the AMX NX-1200 had a routine in place called “setUpSubtleUserAccount.” When that function was enabled it could set up an admin-level account with a hard-coded password, that let it capture data packets from the network the device was connected to.

Recommended Videos

Even more damning is the fact that this created account was also deliberately hidden from the plain-text list of administrative accounts.

Although it is suggested that most AMX hardware would require network connectivity to be able to login to the device, Ars did find some that are connected to the internet and are publicly accessible. That means that, in theory, someone could enable this feature; login remotely and sniff traffic on the network, compromise other accounts, and steal user data; or just listen in to the conferences as they are ongoing.

More worrying still, is that this sort of hardware is sold to many sensitive organizations. According to AMX’s own website, it’s sold AV systems to government, military, educational and healthcare organisations, theoretically creating huge security loopholes in very sensitive environments.

There is also growing evidence that none of this was an accident or created by a wayward employee at AMX. SEC Consult initially contacted AMX about the issue back in March 2015. No response was received for a full seven months, at which time an update was released which AMX claimed had fixed the security problem.

Further investigation revealed however, that although the original subtle admin account was gone, a new backdoor appeared with an almost identical function. When SEC Consult pointed this out to AMX and again received no response, it went public with its concerns.

A public statement has since been released by the AV equipment firm, stating that neither backdoor had anything to do with one another and were not intended for hacking purposes. Instead they were said to be useful diagnostics tools for maintenance, which it says are not accessible from exterior sources. It did however still decide to end support for the original backdoor in its update, so clearly it does see some potential for security issues.

Another update was recently released, however, which may well have shored up all of the backdoors. Or perhaps it will have just hidden them in a more difficult-to-spot manner.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
This Alienware Aurora gaming PC with RTX 5080 is $700 off
Alienware Aurora R16 sitting on a coffee table.

Gamers who are planning to make a huge investment in gaming PC deals should still be on the lookout for opportunities at savings. Dell has an offer that is hard to refuse: a $700 discount on the Alienware Aurora R16 ACT1250 gaming desktop with the Nvidia GeForce RTX 5080 graphics card, bringing its price down to $3,050 from $3,750 originally. It's still expensive, but you might as well take advantage of the lowered price if you're already thinking about spending this much on your PC gaming setup with a 50-series GPU.

Why you should buy the Alienware Aurora R16 ACT1250 gaming PC

Read more
Here’s your chance to buy the Apple MacBook Air M3 for less than $1,000
The MacBook Air on a table in front of a window.

For Apple fans who have been on the lookout for MacBook deals: We've found an interesting one from B&H Photo Video. The 13-inch model of the Apple MacBook Air M3 with 8GB of RAM and a 512GB SSD is on sale for only $899, for savings of $400 on the laptop's original price of $1,299. That's a huge discount that you probably won't find anywhere else, but you'll need to act fast if you're interested in taking advantage of this bargain because it may disappear as soon as tomorrow.

Why you should buy the Apple MacBook Air M3

Read more
The Samsung Odyssey G8 gaming monitor is a steal with this deal
Uncharted Legacy of Thieves collection running on Samsung Odyssey Neo G8.

If your dream PC gaming setup is still missing a screen, we highly recommend taking a look at Samsung monitor deals for nice bargains. Here's one that's available right now: the 32-inch Samsung Odyssey Neo G8 gaming monitor with a $550 discount, which almost halves its original price of $1,300 to only $750. You shouldn't be wasting time though, as the offer may disappear at any moment -- you're going to have to proceed with your purchase immediately in order to secure the savings.

Why you should buy the 32-inch Samsung Odyssey Neo G8 gaming monitor

Read more