CVE-2024-31408

CVSS 3.0 Score 8 of 10 (high)

Details

Published Nov 22, 2024
CWE ID 78

Summary

CVE-2024-31408 is a newly identified vulnerability affecting AIPHONE's IX SYSTEM and IXG SYSTEM. An authenticated attacker, who is network-adjacent, can exploit this OS command injection flaw to execute arbitrary commands with root privileges. The vulnerability arises due to a misconfiguration or weak input validation in the affected software. Successful exploitation could lead to significant security risks, including data breaches and unauthorized system access. It is recommended that users apply the forthcoming patches or updates from AIPHONE to mitigate this vulnerability as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share