CVE-2021-32934
Published: May 19, 2022
Modified: Apr 16, 2025
CVSS v3.1
9.1
Description
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conneciton, firmware using AVAPI module without enabling DTLS mechanism, and firmware using P2PTunnel or RDT module) do not sufficiently protect data transferred between the local device and ThroughTek servers. This can allow an attacker to access sensitive information, such as camera feeds.
| Vendor | Product | Versions |
|---|---|---|
ThroughTek | P2P SDK | affected all with nossl tagunaffected firmware using AuthKey for IOTC connectionaffected firmware using AVAPI module without enabling DTLS mechanismaffected firmware using P2PTunnel or RDT moduleaffected All - <= 3.1.5 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now