We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-31408



Assignerjpcert
Reserved2024-09-26
Published2024-11-22
Updated2024-11-22

Description

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.



HIGH: 8.0CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Product status

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.11 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.7.10 and earlier
affected

firmware Ver.3.01 and earlier
affected

firmware Ver.3.01 and earlier
affected

firmware Ver.3.00 and earlier
affected

firmware Ver.3.00 and earlier
affected

firmware Ver.3.00 and earlier
affected

firmware Ver.3.00 and earlier
affected

firmware Ver.3.00 and earlier
affected

firmware Ver.3.01 and earlier
affected

firmware Ver.3.01 and earlier
affected

firmware Ver.3.00 and earlier
affected

References

https://www.aiphone.net/important/20241016_1/

https://www.aiphone.net/important/20241016_2/

https://www.aiphone.net/support/software-documents/ix/

https://www.aiphone.net/support/software-documents/ixg/

https://jvn.jp/en/jp/JVN41397971/

cve.org CVE-2024-31408

nvd.nist.gov CVE-2024-31408

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-31408
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.