5.9
CVE-2021-40149
- EPSS 59.24%
- Veröffentlicht 17.07.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Reolink ≫ E1 Zoom Firmware Version <= 3.0.0.716
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 59.24% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.