CVE-2024-54847

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cpplusworld:cp-vnr-3104_firmware:b3223p22c02424:*:*:*:*:*:*:*
cpe:2.3:h:cpplusworld:cp-vnr-3104:-:*:*:*:*:*:*:*

History

02 Oct 2025, 17:17

Type Values Removed Values Added
First Time Cpplusworld cp-vnr-3104
Cpplusworld
Cpplusworld cp-vnr-3104 Firmware
CPE cpe:2.3:h:cpplusworld:cp-vnr-3104:-:*:*:*:*:*:*:*
cpe:2.3:o:cpplusworld:cp-vnr-3104_firmware:b3223p22c02424:*:*:*:*:*:*:*
References () https://github.com/Yashodhanvivek/CP-VNR-3104-NVR-Vulnerabilties/blob/main/CPPlus_CP-VNR-3104_Security_Assessment.pdf - () https://github.com/Yashodhanvivek/CP-VNR-3104-NVR-Vulnerabilties/blob/main/CPPlus_CP-VNR-3104_Security_Assessment.pdf - Third Party Advisory
References () https://nvd.nist.gov/vuln/detail/CVE-2023-3817 - () https://nvd.nist.gov/vuln/detail/CVE-2023-3817 - Not Applicable
References () https://payatu.com/blog/solving-the-problem-of-encrypted-firmware/ - () https://payatu.com/blog/solving-the-problem-of-encrypted-firmware/ - Technical Description, Exploit, Third Party Advisory

13 Jan 2025, 21:15

Type Values Removed Values Added
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
Summary
  • (es) Un problema en CP Plus CP-VNR-3104 B3223P22C02424 permite a los atacantes acceder a los parámetros Diffie-Hellman (DH) y acceder a datos confidenciales o ejecutar un ataque de intermediario.

10 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-10 17:15

Updated : 2025-10-02 17:17


NVD link : CVE-2024-54847

Mitre link : CVE-2024-54847

CVE.ORG link : CVE-2024-54847


JSON object : View

Products Affected

cpplusworld

  • cp-vnr-3104
  • cp-vnr-3104_firmware
CWE
CWE-295

Improper Certificate Validation