Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.
References
Link | Resource |
---|---|
https://docs.agora.io/en/Agora%20Platform/downloads | Vendor Advisory |
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/dont-call-us-well-call-you-mcafee-atr-finds-vulnerability-in-agora-video-sdk/ | Exploit Third Party Advisory |
https://docs.agora.io/en/Agora%20Platform/downloads | Vendor Advisory |
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/dont-call-us-well-call-you-mcafee-atr-finds-vulnerability-in-agora-video-sdk/ | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.agora.io/en/Agora%20Platform/downloads - Vendor Advisory | |
References | () https://www.mcafee.com/blogs/other-blogs/mcafee-labs/dont-call-us-well-call-you-mcafee-atr-finds-vulnerability-in-agora-video-sdk/ - Exploit, Third Party Advisory |
Information
Published : 2021-02-17 21:15
Updated : 2024-11-21 05:18
NVD link : CVE-2020-25605
Mitre link : CVE-2020-25605
CVE.ORG link : CVE-2020-25605
JSON object : View
Products Affected
agora
- video_software_development_kit
CWE
CWE-319
Cleartext Transmission of Sensitive Information