CVE-2024-58336

HIGHCVSS 8.7/10EPSS 0.35%

Last modified

CVE-2024-58336 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS 4.0
8.7/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.35%

26.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AkuvoxS539 Firmware912.30.1.137
AkuvoxS532 Firmware912.30.1.137
AkuvoxX916 Firmware912.30.1.137
AkuvoxX915 Firmware912.30.1.137
AkuvoxX912 Firmware912.30.1.137
AkuvoxR29 Firmware912.30.1.137
AkuvoxR20k-2 Firmware912.30.1.137
AkuvoxR20a-2 Firmware912.30.1.137
AkuvoxC313w-2 Firmware912.30.1.137
AkuvoxNs-2 Firmware912.30.1.137
AkuvoxNc-2 Firmware912.30.1.137
AkuvoxNx-2 Firmware912.30.1.137

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-58336?
Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.
How severe is CVE-2024-58336?
CVE-2024-58336 has a CVSS score of 8.7/10 (HIGH severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2024-58336?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-58336?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST