VulnerabilityModified
CVE-2021-40149
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory.
MEDIUM 5.9EPSS 7.93%
Does this matter?
Lower severity and a low EPSS score (7.93%). Track it; it rarely justifies an emergency change on its own.
Description
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 7.93% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552
- Affected
- reolink/e1 zoom firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jun/0Exploit, Mailing List, Third Party Advisory
- https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txtExploit, Third Party Advisory
- http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2022/Jun/0Exploit, Mailing List, Third Party Advisory
- https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.