« Volver al listado

CVE-2020-29001

Estado: ModificadaAlta (7.2)—

An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-29001",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-26T18:15:51.677",
  "references": [
    {
      "url": "https://gist.github.com/tj-oconnor/371d34342c0cc2be015cc89d6dc2bc66",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.mygeeni.com/hc/en-us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/tj-oconnor/371d34342c0cc2be015cc89d6dc2bc66",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.mygeeni.com/hc/en-us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en los dispositivos Geeni GNC-CW028 Camera versión 2.7.2, Geeni GNC-CW025 Doorbell versión 2.9.5, Merkury MI-CW024 Doorbell versión 2.9.6 y Merkury MI-CW017 Camera versión 2.9.6. Se presenta una vulnerabilidad en la API RESTful Services que permite a un atacante remoto tomar el control total de la cámara con una cuenta muy privilegiada. La vulnerabilidad se presenta porque un nombre de usuario y una contraseña estáticos se compilan en la aplicación RESTful ppsapp"
    }
  ],
  "lastModified": "2026-06-17T03:10:57.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:merkuryinnovations:geeni_gnc-cw028_firmware:2.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB35FD64-F869-48E4-8C6D-22259ABA0464"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:merkuryinnovations:geeni_gnc-cw028:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "96C4763A-8411-4C15-96E4-0595ECFC4660"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:merkuryinnovations:geeni_gnc-cw025_firmware:2.9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF9453C9-BE13-44F1-A4A9-EB620A0BCA47"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:merkuryinnovations:geeni_gnc-cw025:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FD78E397-9562-4C63-A631-071BF7973D38"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:merkuryinnovations:merkury_mi-cw024_firmware:2.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6EDB1F0F-5D08-4F8C-BE21-1B3BAE04D05E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:merkuryinnovations:merkury_mi-cw024:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "03699D43-4FB6-4C2E-8A6D-DD8C9339E817"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:merkuryinnovations:merkury_mi-cw017_firmware:2.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7B98574-CB7B-4A4A-A401-135A954E3E27"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:merkuryinnovations:merkury_mi-cw017:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EA760040-B1B6-4264-B881-539EECCAF993"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}