CVE-2020-14033 describes a critical buffer overflow vulnerability in the janus-gateway (Janus WebRTC Server) up to version 0.10.0, specifically within the janus_streaming_rtsp_parse_sdp function. This flaw allows an unauthenticated attacker to achieve full compromise of the affected system (confidentiality, integrity, and availability) by sending a specially crafted RTSP server response. Despite its CVSS score of 9.8 (Critical) and high FAUCET Risk Score, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no known active exploitation. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.10.0CPE matchmatch criteria | cpe:2.3:a:meetecho:janus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.