PT-2022-11191 · Unknown · E1 Zoom Camera
Julien Ahrens
·
Published
2022-06-03
·
Updated
2022-07-27
·
CVE-2021-40149
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
E1 Zoom camera versions 3.0.0.716 and earlier
Description
The web server of the E1 Zoom camera discloses its SSL private key via the root web server directory, allowing an attacker to download the entire key via the "/self.key" URI.
Recommendations
For versions 3.0.0.716 and earlier, as a temporary workaround, consider restricting access to the "/self.key" URI until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E1 Zoom Camera