7.5

CVE-2020-25169

The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera feeds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ReolinkRln8-410 Firmware Version-
   ReolinkRln8-410 Version-
ReolinkRlc-422 Firmware Version-
   ReolinkRlc-422 Version-
ReolinkRlc-510a Firmware Version-
   ReolinkRlc-510a Version-
ReolinkRlc-410 Firmware Version-
   ReolinkRlc-410 Version-
ReolinkRlc-423s Firmware Version-
   ReolinkRlc-423s Version-
ReolinkRlc-423 Firmware Version-
   ReolinkRlc-423 Version-
ReolinkRlc-520a Firmware Version-
   ReolinkRlc-520a Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.308
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.