GeoVision Door Access Control Device - Shared cryptographic keys
CVE-2020-3929

5.9MEDIUM

Key Information:

Vendor

Geovision

Vendor
CVE Published:
12 June 2020

What is CVE-2020-3929?

GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.

Affected Version(s)

Door Access Control Device GV-AS210 <= 2.21

Door Access Control Device GV-AS410 <= 2.21

Door Access Control Device GV-AS810 <= 2.21

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.