Lucene search

K
cve[email protected]CVE-2021-40149
HistoryJul 17, 2022 - 10:15 p.m.

CVE-2021-40149

2022-07-1722:15:08
CWE-552
web.nvd.nist.gov
71
11
cve-2021-40149
e1 zoom camera
web server
ssl private key disclosure
vulnerability

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.009 Low

EPSS

Percentile

83.2%

The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.

Affected configurations

NVD
Node
reolinke1_zoomMatch-
AND
reolinke1_zoom_firmwareRange3.0.0.716

Social References

More

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.009 Low

EPSS

Percentile

83.2%