{"id": "CVE-2020-25173", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2021-01-26T18:15:43.130", "references": [{"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-019-02", "tags": ["Third Party Advisory", "US Government Resource"], "source": "ics-cert@hq.dhs.gov"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-798"}]}, {"type": "Secondary", "source": "ics-cert@hq.dhs.gov", "description": [{"lang": "en", "value": "CWE-321"}]}], "descriptions": [{"lang": "en", "value": "An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access"}, {"lang": "es", "value": "Un atacante con acceso a la red local puede obtener una clave de criptograf\u00eda fija que puede permitir un mayor compromiso de las c\u00e1maras P2P Reolink fuera del acceso a la red local"}], "lastModified": "2021-02-01T19:16:28.453", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rln8-410_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA97CBF4-7E5C-4DF4-99C7-244BC3CC77DC"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rln8-410:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4AE63907-9A5E-46D2-BCE3-41B2B1FD22F6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rlc-422_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE43C3EF-3920-49B9-BB6B-9EA03DDFB954"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rlc-422:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "097FC838-6BEB-4A6E-9ADA-B49F6D926561"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rlc-510a_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C4A48F1-AD16-4499-8D9B-28086287608D"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rlc-510a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "03EA9726-66B7-4B33-A8F3-3421F762CF08"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rlc-423s_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5593386-2933-4692-89C3-F663C83344A5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rlc-423s:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F9DFB155-051D-4EBD-8627-932C81A5027C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rlc-423_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "940DC985-48CA-46E7-8AB0-713688D2CFA6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rlc-423:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E37962D1-C747-4D28-897A-E41A841DE61D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rlc-410_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03CB154B-7116-45B8-875A-CC25991DB230"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rlc-410:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8C158CF9-2697-40AF-9828-C64F3654B097"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:reolink:rlc-520a_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE181027-4C23-4F48-A8A6-96C23382CD99"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:reolink:rlc-520a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "242B396F-15EF-4A4C-AC20-AA7366E0892F"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "ics-cert@hq.dhs.gov"}