2024-12-08 03:06:42 +00:00

193 lines
5.8 KiB
JSON

{
"id": "CVE-2020-25748",
"sourceIdentifier": "cve@mitre.org",
"published": "2020-09-25T04:23:05.107",
"lastModified": "2024-11-21T05:18:39.040",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values."
},
{
"lang": "es",
"value": "Se detect\u00f3 un problema de Transmisi\u00f3n de Texto Sin Cifrar en las c\u00e1maras RV-3406, RV-3409 y RV-3411 de Rubetek (versiones de firmware v342, v339). Alguien en el medio puede interceptar y modificar los datos de video de la c\u00e1mara, que es transmitido en un formulario sin cifrar. Tambi\u00e9n se pueden modificar las respuestas de los servidores NTP y RTSP y forzar la c\u00e1mara para usar los valores modificados"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:rubetek:rv-3406_firmware:339:*:*:*:*:*:*:*",
"matchCriteriaId": "57AF1900-5D42-45B9-9906-B1EBC933A064"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:rubetek:rv-3406_firmware:342:*:*:*:*:*:*:*",
"matchCriteriaId": "72F51EDA-EA7A-4E58-A071-A0D6F3AEC379"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:rubetek:rv-3406:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D0C29138-1CBA-4677-B494-AA5278632606"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:rubetek:rv-3409_firmware:339:*:*:*:*:*:*:*",
"matchCriteriaId": "B2BD4E56-46E1-4985-A46F-C9B4A374A17F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:rubetek:rv-3409_firmware:342:*:*:*:*:*:*:*",
"matchCriteriaId": "EE539B49-BF73-4411-855D-69E02E6AD917"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:rubetek:rv-3409:-:*:*:*:*:*:*:*",
"matchCriteriaId": "93B04FD1-8EEF-4DDC-83A9-9F5390378D28"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:rubetek:rv-3411_firmware:339:*:*:*:*:*:*:*",
"matchCriteriaId": "183C8C01-1F30-40F5-BD9F-6D217EB1CD42"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:rubetek:rv-3411_firmware:342:*:*:*:*:*:*:*",
"matchCriteriaId": "C9ECA3AF-D4F0-4F8B-854C-0C63BB090E44"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:rubetek:rv-3411:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0D54B518-140F-4933-A1C8-45A0A7B3F167"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/jet-pentest/CVE-2020-25748",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://github.com/jet-pentest/CVE-2020-25748",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
}
]
}