CVE-2024-31408

HIGHCVSS 8/10EPSS 1.08%

Last modified

CVE-2024-31408 is a high-severity vulnerability rated 8/10 on the CVSS scale. OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.

Description

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.

Metrics

CVSS 3.0
8/10

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.08%

60.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
AIPHONE CO., LTD.IX-MVfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HBfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HBTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HWfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HWTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HW-JPfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-Bfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-BTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-Wfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-WTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DAUfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DBfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DBTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-EAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-EATfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-EAUfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DVfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVTfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVFfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-Pfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-Lfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVMfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DUfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-2RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-BAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BAUfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BBfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BBTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-FAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SSAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-SS-2Gfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SS-2GTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SS-2G-Nfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BUfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-SSA-RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-SSA-2RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-RS-Bfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-RS-BTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-RS-Wfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-RS-WTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IXW-MAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SPMICfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IXG-2C7firmware Ver.3.01 and earlier
AIPHONE CO., LTD.IXG-2C7-Lfirmware Ver.3.01 and earlier
AIPHONE CO., LTD.IXG-DM7firmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-HIDfirmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-HIDAfirmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-10Kfirmware Ver.3.00 and earlier

Showing 50 of 54 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2024-31408?
OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.
How severe is CVE-2024-31408?
CVE-2024-31408 has a CVSS score of 8/10 (HIGH severity). The EPSS model estimates a 1.08% probability of exploitation in the next 30 days.
How do I fix CVE-2024-31408?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-31408?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST