CVE-2024-45837

MEDIUMCVSS 5.4/10EPSS 0.33%

Last modified

CVE-2024-45837 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.

Description

Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.

Metrics

CVSS 3.0
5.4/10

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS Probability
0.33%

24.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
AIPHONE CO., LTD.IX-MVfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-MV7-HBfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-HBTfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-HWfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-HWTfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-HW-JPfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-Bfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-BTfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-Wfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-MV7-WTfirmware Ver.7.31 and earlier
AIPHONE CO., LTD.IX-DAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DAUfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DBfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DBTfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-EAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-EATfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-EAUfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVTfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVFfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVF-Pfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVF-Lfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVMfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DUfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVF-RAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-DVF-2RAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-BAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-BAUfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-BBfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-BBTfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-FAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SSAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SS-2Gfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SS-2GTfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SS-2G-Nfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-BUfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SSA-RAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SSA-2RAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-RS-Bfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-RS-BTfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-RS-Wfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-RS-WTfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IXW-MAfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IX-SPMICfirmware Ver.7.30 and earlier
AIPHONE CO., LTD.IXG-2C7firmware Ver.3.01 and earlier
AIPHONE CO., LTD.IXG-2C7-Lfirmware Ver.3.01 and earlier
AIPHONE CO., LTD.IXG-DM7firmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-HIDfirmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-HIDAfirmware Ver.3.00 and earlier
AIPHONE CO., LTD.IXG-DM7-10Kfirmware Ver.3.00 and earlier

Showing 50 of 56 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2024-45837?
Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.
How severe is CVE-2024-45837?
CVE-2024-45837 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.33% probability of exploitation in the next 30 days.
How do I fix CVE-2024-45837?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-45837?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST