CVE-2020-3929

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
12/06/2020
Last modified:
18/06/2020

Description

GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:usavisionsys:geovision_gv-as210_firmware:*:*:*:*:*:*:*:* 2.21 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as210:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-as410_firmware:*:*:*:*:*:*:*:* 2.21 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as410:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-as810_firmware:*:*:*:*:*:*:*:* 2.21 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as810:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-as1010_firmware:*:*:*:*:*:*:*:* 1.32 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as1010:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-gf192x_firmware:*:*:*:*:*:*:*:* 1.10 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-gf192x:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools