CVE-2024-5631
CVSS V2 None
CVSS V3 None
Description
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.
The credentials are being sent when a user decides to change his password in router's portal.
Overview
- CVE ID
- CVE-2024-5631
- Assigner
- CERT-PL
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-09T10:57:24.256Z
- Last Modified Date
- 2024-07-09T20:42:03.582Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://zamel.com/pl/gardi/zestaw-monitoringu-bezprzewodowego-wi-fi-typ-zmb-01 | product |
https://cert.pl/en/posts/2024/07/CVE-2024-5631/ | third-party-advisory |
https://cert.pl/posts/2024/07/CVE-2024-5631 | third-party-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-5631 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5631 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-10 13:25:13 | Added to TrackCVE |