CVE-2024-39290

MEDIUMCVSS 6.5/10EPSS 0.37%

Last modified

CVE-2024-39290 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.

Description

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.

Metrics

CVSS 3.0
6.5/10

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.37%

28.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
AIPHONE CO., LTD.IX-MVfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HBfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HBTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HWfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HWTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-HW-JPfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-Bfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-BTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-Wfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-MV7-WTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DAUfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DBfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DBTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-EAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-EATfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-EAUfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DVfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVTfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVFfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-Pfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-Lfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVMfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-DUfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-DVF-2RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-BAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BAUfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BBfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BBTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-FAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SSAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-SS-2Gfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SS-2GTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SS-2G-Nfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-BUfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-SSA-RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-SSA-2RAfirmware Ver.7.11 and earlier
AIPHONE CO., LTD.IX-RS-Bfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-RS-BTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-RS-Wfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-RS-WTfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IXW-MAfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IX-SPMICfirmware Ver.7.10 and earlier
AIPHONE CO., LTD.IXG-2C7firmware Ver.3.01 and earlier
AIPHONE CO., LTD.IXG-2C7-Lfirmware Ver.3.01 and earlier
AIPHONE CO., LTD.IXG-DM7firmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-HIDfirmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-HIDAfirmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-10Kfirmware Ver.3.00 and earlier

Showing 50 of 54 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2024-39290?
Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.
How severe is CVE-2024-39290?
CVE-2024-39290 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.37% probability of exploitation in the next 30 days.
How do I fix CVE-2024-39290?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-39290?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST