VYPR
Unrated severityNVD Advisory· Published Jan 10, 2025· Updated Jan 13, 2025

CVE-2024-54846

CVE-2024-54846

Description

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The CP Plus CP-VNR-3104 NVR firmware B3223P22C02424 exposes the EC private key, enabling attackers to decrypt communications and perform man-in-the-middle attacks.

Vulnerability

The CP Plus CP-VNR-3104 network video recorder (NVR) running firmware version B3223P22C02424 contains a flaw that allows an attacker to obtain the device's Elliptic Curve (EC) private key. This key is used for secure communications and authentication. The vulnerability likely stems from improper storage or generation of the cryptographic key material within the firmware [3].

Exploitation

An attacker with network access to the NVR can extract the EC private key without authentication. The exact method is detailed in the security assessment [3], but it involves exploiting a weakness in the key management implementation. No user interaction is required, and the attacker can be on the same network segment.

Impact

Successful extraction of the EC private key allows the attacker to decrypt all encrypted traffic to and from the NVR, access sensitive data such as video streams and credentials, and perform man-in-the-middle attacks to impersonate the device or intercept communications. The attacker gains the ability to compromise the confidentiality and integrity of the NVR's communications.

Mitigation

As of the publication date (2025-01-10), no official patch has been released by CP Plus. The affected firmware version B3223P22C02424 is confirmed vulnerable. Users should monitor vendor advisories for a firmware update. In the interim, network segmentation and strict access controls can reduce exposure. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • CP Plus/CP-VNR-3104cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = B3223P22C02424

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.