2019-12-20 18:01:04 +00:00
{
"CVE_data_meta" : {
2020-06-12 16:20:24 +08:00
"AKA" : "TWCERT/CC" ,
2020-06-12 09:01:28 +00:00
"ASSIGNER" : "cve@cert.org.tw" ,
2020-06-12 16:20:24 +08:00
"DATE_PUBLIC" : "2020-06-12T08:00:00.000Z" ,
2019-12-20 18:01:04 +00:00
"ID" : "CVE-2020-3929" ,
2020-06-12 16:20:24 +08:00
"STATE" : "PUBLIC" ,
"TITLE" : "GeoVision Door Access Control Device - Shared cryptographic keys"
2019-12-20 18:01:04 +00:00
} ,
2020-06-12 16:20:24 +08:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Door Access Control Device" ,
"version" : {
"version_data" : [
{
"version_affected" : "<=" ,
"version_name" : "GV-AS210" ,
"version_value" : "2.21"
} ,
{
"version_affected" : "<=" ,
"version_name" : "GV-AS410" ,
"version_value" : "2.21"
} ,
{
"version_affected" : "<=" ,
"version_name" : "GV-AS810" ,
"version_value" : "2.21"
} ,
{
"version_affected" : "<=" ,
"version_name" : "GV-GF192x" ,
"version_value" : "1.10"
} ,
{
"version_affected" : "<=" ,
"version_name" : "GV-AS1010" ,
"version_value" : "1.32"
}
]
}
}
]
} ,
"vendor_name" : "GeoVision"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2019-12-20 18:01:04 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2020-06-12 09:01:28 +00:00
"value" : "GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages."
2020-06-12 16:20:24 +08:00
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"impact" : {
"cvss" : {
"attackComplexity" : "HIGH" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.9 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "NONE" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"version" : "3.1"
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "Shared cryptographic keys"
}
]
2019-12-20 18:01:04 +00:00
}
]
2020-06-12 16:20:24 +08:00
} ,
"references" : {
"reference_data" : [
{
2020-06-12 09:01:28 +00:00
"refsource" : "MISC" ,
"url" : "https://www.twcert.org.tw/tw/cp-132-3696-6601c-1.html" ,
"name" : "https://www.twcert.org.tw/tw/cp-132-3696-6601c-1.html"
2020-06-12 16:20:24 +08:00
}
]
} ,
"solution" : [
{
"lang" : "eng" ,
"value" : "Update to version 2.22 in GV-AS210\nUpdate to version 2.22 in GV-AS410\nUpdate to version 2.22 in GV-AS810\nUpdate to version 1.22 in GV-GF192x\nUpdate to version 1.33 in GV-AS1010"
}
] ,
"source" : {
"discovery" : "UNKNOWN"
2019-12-20 18:01:04 +00:00
}
}