Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.
https://payatu.com/blog/solving-the-problem-of-encrypted-firmware/
https://nvd.nist.gov/vuln/detail/CVE-2021-21551
https://github.com/Yashodhanvivek/CP-VNR-3104-NVR-Vulnerabilties/blob/main/CPPlus_CP-VNR-3104_Security_Assessment.pdf
https://capec.mitre.org/data/definitions/233
Source: Mitre, NVD
Published: 2025-01-10
Updated: 2025-01-13
Base Score: 5.8
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 7.4
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: High