8.1

CVE-2020-25748

A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RubetekRv-3406 Firmware Version339
   RubetekRv-3406 Version-
RubetekRv-3406 Firmware Version342
   RubetekRv-3406 Version-
RubetekRv-3409 Firmware Version339
   RubetekRv-3409 Version-
RubetekRv-3409 Firmware Version342
   RubetekRv-3409 Version-
RubetekRv-3411 Firmware Version339
   RubetekRv-3411 Version-
RubetekRv-3411 Firmware Version342
   RubetekRv-3411 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.447
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.