CVE-2020-3929
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.21 |
| Running on/with | Platform Versions |
|---|---|
Usavisionsys Geovision Gv As210 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.21 |
| Running on/with | Platform Versions |
|---|---|
Usavisionsys Geovision Gv As410 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.21 |
| Running on/with | Platform Versions |
|---|---|
Usavisionsys Geovision Gv As810 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.32 |
| Running on/with | Platform Versions |
|---|---|
Usavisionsys Geovision Gv As1010 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.10 |
| Running on/with | Platform Versions |
|---|---|
Usavisionsys Geovision Gv Gf192x | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.