CVE-2024-58337
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.
Affected (13)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox S539 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox S532 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox X916 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox X915 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox X912 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox R29 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox E16c | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox R20k 2 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox R20a 2 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox C313w 2 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox Ns 2 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox Nc 2 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 912.30.1.137 |
| Running on/with | Platform Versions |
|---|---|
Akuvox Nx 2 | All versions |
References (5)
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory
Timeline
No history available yet.