Security Advisory

Update History: August 4, 2025 at 9:45AM EST – Published

Affected Products and Firmware Versions:

  • HALO 3C devices running firmware version 2.15.0.13 or lower
  • HALO 2/2C devices running firmware version 2.14.3.0 or lower

Vulnerability Description and Potential Impact:

If exploited, these critical vulnerabilities could allow an attacker to gain unauthorized access and control of a HALO device. This includes the ability to bypass web portal login protections through brute-force attacks and, more critically, to install unauthorized or malicious firmware. We are not aware of any exploitation in our customers’ environments, but immediate steps should be taken to safeguard devices.

Recommended Remediation – Immediate Action Required:

The most effective remediation is to ensure your HALO devices are running the latest firmware, which addresses these critical vulnerabilities. Firmware version 2.17.0.2 specifically addresses the vulnerabilities identified in this notice.

  • For devices connected to the HALO cloud, Motorola Solutions will automatically apply the update to all cloud-connected devices.(Please note: This excludes customers who have opted out of automatic updates.)
  • For devices that are NOT connected to the HALO cloud: Administrators must download the latest firmware from https://halodetect.com/firmware-tools/ and install it manually on each device utilizing the latest version of the Halo Device Manager tool found on the same web page.

Additional Cybersecurity Best Practices:

We strongly remind all users of these general cybersecurity best practices:

  • Keep firmware current: Always ensure your HALO devices are running the latest firmware to benefit from the newest functionalities, bug fixes, and security updates.
  • Isolate your network: Do not operate HALO devices on the same network as public Wi-Fi or other networks accessible to the public.
  • Use strong passwords: Enforce the use of strong passwords for HALO devices’ web interfaces. We recommend using strong passwords of at least 16 characters.

Our Commitment to Security:

Motorola Solutions responsibly designs, hardens, and tests our solutions to incorporate key data security principles from the start, and we align with well-recognized information security standards. For example:

  • Our approach to design follows industry best practices for cybersecurity and implements controls that support the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
  • We hold certifications from the International Organization for Standardization (ISO) 27000 Series, demonstrating our commitment to and compliance with effective information security and privacy management.

Questions or Assistance:

For questions or assistance with upgrading HALO firmware, please contact Motorola Solutions Technical Support at 866-797-1300.

Update History: January 18, 2024 at 9:45AM EST – Published

No Security Vulnerabilities

Update History: September 18, 2023 at 3:00PM EST – Published

No Security Vulnerabilities

Update History: December 14, 2021, at 4:30PM EST – Published

Log4j2 Vulnerability Assessment

Overview

IPVideo Corporation is aware of the Log4j2 vulnerability CVE – CVE-2021-44228 (mitre.org) and our product, operations, and security teams are currently assessing all products.

As always, please follow cybersecurity best practices including ensuring all of your servers are properly secured behind firewalls, backed up, and not left unprotected on the internet if they are installed on-premises.

Please check back to this site regularly as we will continue to post updates as new information becomes available.

Current Status:

IPVideo Corporation has been performing a review of our products, code and production environments. Currently, our analysis indicates that the products listed below are not affected by this vulnerability. As this is an evolving threat, we will update this site as new information becomes available.

  • HALO V2.0
  • HALO V2C
  • HALO Cloud
  • AVfusion
  • ViewScan

Important Notes:

  1. While the AVfusion and ViewScan products are not affected, customers should investigate the environment where they have installed the product(s) to ensure the operating systems, other software installed on the server and virtual environments are not affected. For example, VMware is commonly used to virtualize the underlying infrastructure and they have provided an update on their products at the following link: https://www.vmware.com/security/advisories/VMSA-2021-0028.html
  2. Our analysis was done on the latest released version of each product. SaaS products are always on the latest version, but for on-premises products, you should ensure you have updated to the latest version.
  3. Our HALO Cloud backend utilizes Amazon Web Services. Amazon has addressed the vulnerability and we are actively monitoring their updates.

https://aws.amazon.com/security/security-bulletins/AWS-2021-006/