CVE-2024-58337

HIGHCVSS 8.7/10EPSS 0.21%

Last modified

CVE-2024-58337 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.

Metrics

CVSS 3.1
4.3/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CVSS 4.0
8.7/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.21%

11.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AkuvoxS539 Firmware912.30.1.137
AkuvoxS532 Firmware912.30.1.137
AkuvoxX916 Firmware912.30.1.137
AkuvoxX915 Firmware912.30.1.137
AkuvoxX912 Firmware912.30.1.137
AkuvoxR29 Firmware912.30.1.137
AkuvoxE16c Firmware912.30.1.137
AkuvoxR20k-2 Firmware912.30.1.137
AkuvoxR20a-2 Firmware912.30.1.137
AkuvoxC313w-2 Firmware912.30.1.137
AkuvoxNs-2 Firmware912.30.1.137
AkuvoxNc-2 Firmware912.30.1.137
AkuvoxNx-2 Firmware912.30.1.137

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-58337?
Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.
How severe is CVE-2024-58337?
CVE-2024-58337 has a CVSS score of 8.7/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2024-58337?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-58337?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST