CVE-2020-9526
Summary
| CVE | CVE-2020-9526 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-10 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices. |
Risk And Classification
Problem Types: CWE-327 | CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cs2-network | P2p | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security cameras vulnerable to hijacking | MISC | hacked.camera | Third Party Advisory |
| Security cameras vulnerable to hijacking | MISC | redprocyon.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.