PT-2021-19981 · Throughtek · Throughtek P2P
Published
2021-06-16
·
Updated
2022-06-06
·
CVE-2021-32934
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ThroughTek P2P products versions prior to 3.1.5
ThroughTek P2P products with nossl tag
ThroughTek P2P products with device firmware not using AuthKey for IOTC connection
ThroughTek P2P products with firmware using AVAPI module without enabling DTLS mechanism
ThroughTek P2P products with firmware using P2PTunnel or RDT module
Description
The affected ThroughTek P2P products do not sufficiently protect data transferred between the local device and ThroughTek servers. This can allow an attacker to access sensitive information, such as camera feeds.
Recommendations
For ThroughTek P2P products versions prior to 3.1.5, update to version 3.1.5 or later.
For ThroughTek P2P products with nossl tag, remove the nossl tag and enable SSL.
For ThroughTek P2P products with device firmware not using AuthKey for IOTC connection, enable AuthKey for IOTC connection.
For ThroughTek P2P products with firmware using AVAPI module without enabling DTLS mechanism, enable DTLS mechanism for the AVAPI module.
For ThroughTek P2P products with firmware using P2PTunnel or RDT module, consider disabling the P2PTunnel or RDT module until a patch is available.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Throughtek P2P