Vulnerability Description
GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Usavisionsys | Geovision Gv-As210 Firmware | < 2.21 |
| Usavisionsys | Geovision Gv-As210 | - |
| Usavisionsys | Geovision Gv-As410 Firmware | < 2.21 |
| Usavisionsys | Geovision Gv-As410 | - |
| Usavisionsys | Geovision Gv-As810 Firmware | < 2.21 |
| Usavisionsys | Geovision Gv-As810 | - |
| Usavisionsys | Geovision Gv-As1010 Firmware | < 1.32 |
| Usavisionsys | Geovision Gv-As1010 | - |
| Usavisionsys | Geovision Gv-Gf192X Firmware | < 1.10 |
| Usavisionsys | Geovision Gv-Gf192X | - |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-3696-6601c-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-3696-6601c-1.htmlThird Party Advisory
FAQ
What is CVE-2020-3929?
CVE-2020-3929 is a vulnerability with a CVSS score of 5.9 (MEDIUM). GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted mess...
How severe is CVE-2020-3929?
CVE-2020-3929 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3929?
Check the references section above for vendor advisories and patch information. Affected products include: Usavisionsys Geovision Gv-As210 Firmware, Usavisionsys Geovision Gv-As210, Usavisionsys Geovision Gv-As410 Firmware, Usavisionsys Geovision Gv-As410, Usavisionsys Geovision Gv-As810 Firmware.