CVE-2020-9526

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices.
References
Link Resource
https://hacked.camera/ Third Party Advisory
https://redprocyon.com Third Party Advisory
https://hacked.camera/ Third Party Advisory
https://redprocyon.com Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cs2-network:p2p:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:40

Type Values Removed Values Added
References () https://hacked.camera/ - Third Party Advisory () https://hacked.camera/ - Third Party Advisory
References () https://redprocyon.com - Third Party Advisory () https://redprocyon.com - Third Party Advisory

Information

Published : 2020-08-10 16:15

Updated : 2024-11-21 05:40


NVD link : CVE-2020-9526

Mitre link : CVE-2020-9526

CVE.ORG link : CVE-2020-9526


JSON object : View

Products Affected

cs2-network

  • p2p
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-327

Use of a Broken or Risky Cryptographic Algorithm