GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Usavisionsys
Subscribe
|
Geovision Gv-as1010
Subscribe
Geovision Gv-as1010 Firmware
Subscribe
Geovision Gv-as210
Subscribe
Geovision Gv-as210 Firmware
Subscribe
Geovision Gv-as410
Subscribe
Geovision Gv-as410 Firmware
Subscribe
Geovision Gv-as810
Subscribe
Geovision Gv-as810 Firmware
Subscribe
Geovision Gv-gf192x
Subscribe
Geovision Gv-gf192x Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-25194 | GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages. |
Fixes
Solution
Update to version 2.22 in GV-AS210 Update to version 2.22 in GV-AS410 Update to version 2.22 in GV-AS810 Update to version 1.22 in GV-GF192x Update to version 1.33 in GV-AS1010
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-3696-6601c-1.html |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T02:26:42.600Z
Reserved: 2019-12-20T00:00:00
Link: CVE-2020-3929
No data.
Status : Modified
Published: 2020-06-12T09:15:10.380
Modified: 2024-11-21T05:31:58.740
Link: CVE-2020-3929
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD