CVE-2020-25605

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
17/02/2021
Last modified:
23/02/2021

Description

Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:agora:video_software_development_kit:*:*:*:*:*:*:*:* 3.1 (excluding)