Cryptographic Vulnerability in CP Plus NVR Product Line
CVE-2024-54846

5.9MEDIUM

Key Information:

Vendor

CP Plus

Vendor
CVE Published:
10 January 2025

What is CVE-2024-54846?

A security issue has been identified in the CP Plus CP-VNR-3104 model, which allows attackers to exploit the system and retrieve the elliptic Curve private key. This vulnerability can lead to serious consequences, including unauthorized access to sensitive data and the potential for man-in-the-middle attacks, putting the integrity and confidentiality of communications at risk. Users of this specific model should take immediate preventive measures to secure their systems against these threats.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.