CVE-2024-45837
CVSS 3.0 Score 5.4 of 10 (medium)
Details
Published Nov 22, 2024
CWE ID 321
Summary
CVE-2024-45837 is a vulnerability affecting AIPHONE's IX SYSTEM, IXG SYSTEM, and System Support Software. This issue involves the use of a hard-coded cryptographic key, which allows a network-adjacent, unauthenticated attacker to gain access to the SFTP service. Once obtained, the attacker can manipulate unauthorized files, posing a significant risk to sensitive data and system integrity. This vulnerability requires immediate attention from affected organizations, who should apply the necessary patches or upgrades to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.