CVE-2024-12897

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Dec 23, 2024
Updated: Dec 27, 2024
CWE ID 23
CWE ID 24

Summary

CVE-2024-12897 is a newly disclosed critical vulnerability that affects Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3, and VIP S4320 G2 up to version 20241222. The issue lies within an unknown part of the file ../mtd/Config/Sha1Account1 in the Web Interface component. An attacker can manipulate this vulnerability to initiate a path traversal attack, specifically '../filedir'. This exploit is remotely executable and has been made public, increasing the risk for potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share