Lucene search

K
cveIcscertCVE-2021-32934
HistoryMay 19, 2022 - 6:15 p.m.

CVE-2021-32934

2022-05-1918:15:09
CWE-319
icscert
web.nvd.nist.gov
57
11
cve-2021-32934
throughtek
p2p
sdks
nossl
authkey
iotc connection
avapi
dtls
p2ptunnel
rdt
data protection
sensitive information
camera feeds

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

50.5%

The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conneciton, firmware using AVAPI module without enabling DTLS mechanism, and firmware using P2PTunnel or RDT module) do not sufficiently protect data transferred between the local device and ThroughTek servers. This can allow an attacker to access sensitive information, such as camera feeds.

Affected configurations

Nvd
Node
throughtekkalay_p2p_software_development_kitRange3.1.5
VendorProductVersionCPE
throughtekkalay_p2p_software_development_kit*cpe:2.3:a:throughtek:kalay_p2p_software_development_kit:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "P2P SDK",
    "vendor": "ThroughTek",
    "versions": [
      {
        "status": "affected",
        "version": "all with nossl tag"
      },
      {
        "status": "unaffected",
        "version": "firmware using AuthKey for IOTC connection"
      },
      {
        "status": "affected",
        "version": "firmware using AVAPI module without enabling DTLS mechanism"
      },
      {
        "status": "affected",
        "version": "firmware using P2PTunnel or RDT module"
      },
      {
        "lessThanOrEqual": "3.1.5",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

50.5%