MEDIUM · 4.3

CVE-2024-58337

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulne...

Vulnerability Description

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
AkuvoxS539 Firmware912.30.1.137
AkuvoxS539-
AkuvoxS532 Firmware912.30.1.137
AkuvoxS532-
AkuvoxX916 Firmware912.30.1.137
AkuvoxX916-
AkuvoxX915 Firmware912.30.1.137
AkuvoxX915-
AkuvoxX912 Firmware912.30.1.137
AkuvoxX912-
AkuvoxR29 Firmware912.30.1.137
AkuvoxR29-
AkuvoxE16C Firmware912.30.1.137
AkuvoxE16C-
AkuvoxR20K-2 Firmware912.30.1.137
AkuvoxR20K-2-
AkuvoxR20A-2 Firmware912.30.1.137
AkuvoxR20A-2-
AkuvoxC313W-2 Firmware912.30.1.137
AkuvoxC313W-2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-58337?

CVE-2024-58337 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulne...

How severe is CVE-2024-58337?

CVE-2024-58337 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-58337?

Check the references section above for vendor advisories and patch information. Affected products include: Akuvox S539 Firmware, Akuvox S539, Akuvox S532 Firmware, Akuvox S532, Akuvox X916 Firmware.