Описание
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.0.716 (включая)
Одновременно
cpe:2.3:o:reolink:e1_zoom_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:reolink:e1_zoom:-:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.59239
Средний
5.9 Medium
CVSS3
Дефекты
CWE-552
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
EPSS
Процентиль: 98%
0.59239
Средний
5.9 Medium
CVSS3
Дефекты
CWE-552