PT-2022-11191 · Unknown · E1 Zoom Camera

Julien Ahrens

·

Published

2022-06-03

·

Updated

2022-07-27

·

CVE-2021-40149

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions E1 Zoom camera versions 3.0.0.716 and earlier
Description The web server of the E1 Zoom camera discloses its SSL private key via the root web server directory, allowing an attacker to download the entire key via the "/self.key" URI.
Recommendations For versions 3.0.0.716 and earlier, as a temporary workaround, consider restricting access to the "/self.key" URI until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40149

Affected Products

E1 Zoom Camera