Vulnerability Description
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cs2-Network | P2P | <= 3.0.3a |
Related Weaknesses (CWE)
References
- https://hacked.cameraThird Party Advisory
- https://redprocyon.comThird Party Advisory
- https://hacked.cameraThird Party Advisory
- https://redprocyon.comThird Party Advisory
FAQ
What is CVE-2020-9525?
CVE-2020-9525 is a vulnerability with a CVSS score of 8.1 (HIGH). CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated ...
How severe is CVE-2020-9525?
CVE-2020-9525 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9525?
Check the references section above for vendor advisories and patch information. Affected products include: Cs2-Network P2P.