CVE-2024-58336
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox S539 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox S532 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox X916 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox X915 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox X912 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox R29 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox R20k 2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox R20a 2 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox C313w 2 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox Ns 2 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox Nc 2 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox Nx 2 | All versions |
References (4)
https://www.vulncheck.com/advisories/akuvox-smart-intercom-s-unauthenticated-video-stream-disclosure
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory
Timeline
No history available yet.