Cryptographic Vulnerability in CP Plus Security Camera Model
CVE-2024-54849

5.9MEDIUM

Key Information:

Vendor

CP Plus

Vendor
CVE Published:
10 January 2025

What is CVE-2024-54849?

A vulnerability exists in the CP Plus CP-VNR-3104 B3223P22C02424 that permits attackers to extract the second RSA private key. This exposure could enable unauthorized parties to gain access to sensitive information or mount a man-in-the-middle attack, compromising the integrity and confidentiality of the data transmitted. Organizations utilizing this product should urgently assess their security posture and apply necessary patches to mitigate potential risks.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.