← back
CVE-2020-3929

GeoVision Door Access Control Device - Shared cryptographic keys

CVSS 5.9 MEDIUMEPSS 0.5%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Jun 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →