« Volver al listado

CVE-2024-47142

Estado: AplazadaMedia (5.5)—

AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-47142",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-47142",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-22T11:29:13.255927Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "AIPHONE CO., LTD.",
          "product": "IXG-2C7",
          "versions": [
            {
              "status": "affected",
              "version": "firmware Ver.2.03 and earlier"
            }
          ]
        },
        {
          "vendor": "AIPHONE CO., LTD.",
          "product": "IXG-2C7-L",
          "versions": [
            {
              "status": "affected",
              "version": "firmware Ver.2.03 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-11-22T02:15:21.280",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN41397971/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.aiphone.net/important/20241016_2/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.aiphone.net/support/software-documents/ixg/",
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations."
    },
    {
      "lang": "es",
      "value": "El firmware AIPHONE IXG SYSTEM IXG-2C7, versión 2.03 y anteriores, y el firmware IXG-2C7-L, versión 2.03 y anteriores, contienen un problema con credenciales insuficientemente protegidas, lo que puede permitir que un atacante autenticado adyacente a la red realice operaciones no deseadas."
    }
  ],
  "lastModified": "2026-06-17T07:56:37.203",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}