CVE-2020-9525

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/08/2020
Last modified:
21/07/2021

Description

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cs2-network:p2p:*:*:*:*:*:*:*:* 3.0.3a (including)


References to Advisories, Solutions, and Tools