Vulnerability Name: | CVE-2020-12110 (CCN-181258) |
Assigned: | 2020-04-29 |
Published: | 2020-04-29 |
Updated: | 2020-05-12 |
Summary: | Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
|
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-798
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2020-12110
Source: MISC Type: Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/157532/TP-LINK-Cloud-Cameras-NCXXX-Hardcoded-Encryption-Key.html
Source: XF Type: UNKNOWN tplink-cve202012110-info-disc(181258)
Source: CCN Type: Packet Storm Security [05-01-2020] TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key
Source: CCN Type: Full-Disclosure Mailing List, Wed, 29 Apr 2020 23:44:43 +0100 TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key
Source: MISC Type: Exploit, Mailing List, Third Party Advisory https://seclists.org/fulldisclosure/2020/May/3
Source: CCN Type: TP-Link Web site NC series Cloud Cameras
|
Vulnerable Configuration: | Configuration 1: cpe:/o:tp-link:nc200_firmware:2.1.6:160108_b:*:*:*:*:*:*OR cpe:/o:tp-link:nc200_firmware:2.1.9:200225:*:*:*:*:*:*AND cpe:/h:tp-link:nc200:-:*:*:*:*:*:*:* Configuration 2: cpe:/o:tp-link:nc210_firmware:1.0.3:160229:*:*:*:*:*:*OR cpe:/o:tp-link:nc210_firmware:1.0.4:160412:*:*:*:*:*:*OR cpe:/o:tp-link:nc210_firmware:1.0.9:200304:*:*:*:*:*:*AND cpe:/h:tp-link:nc210:-:*:*:*:*:*:*:* Configuration 3: cpe:/o:tp-link:nc220_firmware:1.2.0:170516:*:*:*:*:*:*OR cpe:/o:tp-link:nc220_firmware:1.3.0:180105:*:*:*:*:*:*OR cpe:/o:tp-link:nc220_firmware:1.3.0:200304:*:*:*:*:*:*AND cpe:/h:tp-link:nc220:-:*:*:*:*:*:*:* Configuration 4: cpe:/o:tp-link:nc230_firmware:1.0.3:160108:*:*:*:*:*:*OR cpe:/o:tp-link:nc230_firmware:1.2.1:170515:*:*:*:*:*:*OR cpe:/o:tp-link:nc230_firmware:1.3.0:200304:*:*:*:*:*:*AND cpe:/h:tp-link:nc230:-:*:*:*:*:*:*:* Configuration 5: cpe:/o:tp-link:nc250_firmware:1.0.8:160108:*:*:*:*:*:*OR cpe:/o:tp-link:nc250_firmware:1.0.10:160321:*:*:*:*:*:*OR cpe:/o:tp-link:nc250_firmware:1.2.1:170515:*:*:*:*:*:*OR cpe:/o:tp-link:nc250_firmware:1.3.0:200304:*:*:*:*:*:*AND cpe:/h:tp-link:nc250:-:*:*:*:*:*:*:* Configuration 6: cpe:/o:tp-link:nc260_firmware:1.0.5:160804:*:*:*:*:*:*OR cpe:/o:tp-link:nc260_firmware:1.0.6:161114:*:*:*:*:*:*OR cpe:/o:tp-link:nc260_firmware:1.4.1:180720:*:*:*:*:*:*OR cpe:/o:tp-link:nc260_firmware:1.5.0:181123:*:*:*:*:*:*OR cpe:/o:tp-link:nc260_firmware:1.5.2:200304:*:*:*:*:*:*AND cpe:/h:tp-link:nc260:-:*:*:*:*:*:*:* Configuration 7: cpe:/o:tp-link:nc450_firmware:1.0.15:160920:*:*:*:*:*:*OR cpe:/o:tp-link:nc450_firmware:1.1.2:161013:*:*:*:*:*:*OR cpe:/o:tp-link:nc450_firmware:1.3.4:171130:*:*:*:*:*:*OR cpe:/o:tp-link:nc450_firmware:1.5.3:200304:*:*:*:*:*:*AND cpe:/h:tp-link:nc450:-:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |
tp-link nc200 firmware 2.1.6 160108_b
tp-link nc200 firmware 2.1.9 200225
tp-link nc200 -
tp-link nc210 firmware 1.0.3 160229
tp-link nc210 firmware 1.0.4 160412
tp-link nc210 firmware 1.0.9 200304
tp-link nc210 -
tp-link nc220 firmware 1.2.0 170516
tp-link nc220 firmware 1.3.0 180105
tp-link nc220 firmware 1.3.0 200304
tp-link nc220 -
tp-link nc230 firmware 1.0.3 160108
tp-link nc230 firmware 1.2.1 170515
tp-link nc230 firmware 1.3.0 200304
tp-link nc230 -
tp-link nc250 firmware 1.0.8 160108
tp-link nc250 firmware 1.0.10 160321
tp-link nc250 firmware 1.2.1 170515
tp-link nc250 firmware 1.3.0 200304
tp-link nc250 -
tp-link nc260 firmware 1.0.5 160804
tp-link nc260 firmware 1.0.6 161114
tp-link nc260 firmware 1.4.1 180720
tp-link nc260 firmware 1.5.0 181123
tp-link nc260 firmware 1.5.2 200304
tp-link nc260 -
tp-link nc450 firmware 1.0.15 160920
tp-link nc450 firmware 1.1.2 161013
tp-link nc450 firmware 1.3.4 171130
tp-link nc450 firmware 1.5.3 200304
tp-link nc450 -