CVE-2024-3160

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 2, 2024
Updated: Aug 1, 2024
CWE ID 79

Summary

CVE-2024-3160 is a disputed vulnerability affecting Intelbras MHDX 1004, MHDX 1008, MHDX 1016, MHDX 5016, HDCVI 1008, and HDCVI 1016 up to April 2024. The issue lies within the file /cap.js of the HTTP GET Request Handler, which, if manipulated, leads to information disclosure. This vulnerability is remotely exploitable and the exploit has been disclosed to the public. However, the existence of this vulnerability and its potential impact on users is currently under debate. A separate identifier, VDB-258933, has been assigned to this issue. Intelbras maintains that the information disclosed is not sensitive and therefore no vulnerability exists.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share