« Volver al listado

CVE-2020-25748

Estado: ModificadaAlta (8.1)—

A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-25748",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-25T04:23:05.107",
  "references": [
    {
      "url": "https://github.com/jet-pentest/CVE-2020-25748",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/jet-pentest/CVE-2020-25748",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema de Transmisión de Texto Sin Cifrar en las cámaras RV-3406, RV-3409 y RV-3411 de Rubetek (versiones de firmware v342, v339). Alguien en el medio puede interceptar y modificar los datos de video de la cámara, que es transmitido en un formulario sin cifrar. También se pueden modificar las respuestas de los servidores NTP y RTSP y forzar la cámara para usar los valores modificados"
    }
  ],
  "lastModified": "2026-06-17T03:07:14.080",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3406_firmware:339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57AF1900-5D42-45B9-9906-B1EBC933A064"
            },
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3406_firmware:342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72F51EDA-EA7A-4E58-A071-A0D6F3AEC379"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rubetek:rv-3406:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D0C29138-1CBA-4677-B494-AA5278632606"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3409_firmware:339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2BD4E56-46E1-4985-A46F-C9B4A374A17F"
            },
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3409_firmware:342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE539B49-BF73-4411-855D-69E02E6AD917"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rubetek:rv-3409:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "93B04FD1-8EEF-4DDC-83A9-9F5390378D28"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3411_firmware:339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "183C8C01-1F30-40F5-BD9F-6D217EB1CD42"
            },
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3411_firmware:342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9ECA3AF-D4F0-4F8B-854C-0C63BB090E44"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rubetek:rv-3411:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0D54B518-140F-4933-A1C8-45A0A7B3F167"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}