CVE-2021-40149
Summary
| CVE | CVE-2021-40149 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-17 22:15:00 UTC |
| Updated | 2022-07-27 17:21:00 UTC |
| Description | The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI. |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Reolink | E1 Zoom | - | All | All | All |
| Operating System | Reolink | E1 Zoom Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| advisories/CVE-2021-40149.txt at master · MrTuxracer/advisories · GitHub | MISC | github.com | |
| Reolink E1 Zoom Camera 3.0.0.716 Private Key Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Full Disclosure: [CVE-2021-40149] Reolink E1 Zoom Camera <= 3.0.0.716 Unauthenticated Private Key Disclosure | MISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.