CVE-2024-39290

Description

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.

Category

6.5
CVSS
Severity: Medium
CVSS 3.0 •
EPSS 0.03%
Affected: AIPHONE CO., LTD. IX-MV
Affected: AIPHONE CO., LTD. IX-MV7-HB
Affected: AIPHONE CO., LTD. IX-MV7-HBT
Affected: AIPHONE CO., LTD. IX-MV7-HW
Affected: AIPHONE CO., LTD. IX-MV7-HWT
Affected: AIPHONE CO., LTD. IX-MV7-HW-JP
Affected: AIPHONE CO., LTD. IX-MV7-B
Affected: AIPHONE CO., LTD. IX-MV7-BT
Affected: AIPHONE CO., LTD. IX-MV7-W
Affected: AIPHONE CO., LTD. IX-MV7-WT
Affected: AIPHONE CO., LTD. IX-DA
Affected: AIPHONE CO., LTD. IX-DAU
Affected: AIPHONE CO., LTD. IX-DB
Affected: AIPHONE CO., LTD. IX-DBT
Affected: AIPHONE CO., LTD. IX-EA
Affected: AIPHONE CO., LTD. IX-EAT
Affected: AIPHONE CO., LTD. IX-EAU
Affected: AIPHONE CO., LTD. IX-DV
Affected: AIPHONE CO., LTD. IX-DVT
Affected: AIPHONE CO., LTD. IX-DVF
Affected: AIPHONE CO., LTD. IX-DVF-P
Affected: AIPHONE CO., LTD. IX-DVF-L
Affected: AIPHONE CO., LTD. IX-DVM
Affected: AIPHONE CO., LTD. IX-DU
Affected: AIPHONE CO., LTD. IX-DVF-RA
Affected: AIPHONE CO., LTD. IX-DVF-2RA
Affected: AIPHONE CO., LTD. IX-BA
Affected: AIPHONE CO., LTD. IX-BAU
Affected: AIPHONE CO., LTD. IX-BB
Affected: AIPHONE CO., LTD. IX-BBT
Affected: AIPHONE CO., LTD. IX-FA
Affected: AIPHONE CO., LTD. IX-SSA
Affected: AIPHONE CO., LTD. IX-SS-2G
Affected: AIPHONE CO., LTD. IX-SS-2GT
Affected: AIPHONE CO., LTD. IX-SS-2G-N
Affected: AIPHONE CO., LTD. IX-BU
Affected: AIPHONE CO., LTD. IX-SSA-RA
Affected: AIPHONE CO., LTD. IX-SSA-2RA
Affected: AIPHONE CO., LTD. IX-RS-B
Affected: AIPHONE CO., LTD. IX-RS-BT
Affected: AIPHONE CO., LTD. IX-RS-W
Affected: AIPHONE CO., LTD. IX-RS-WT
Affected: AIPHONE CO., LTD. IXW-MA
Affected: AIPHONE CO., LTD. IX-SPMIC
Affected: AIPHONE CO., LTD. IXG-2C7
Affected: AIPHONE CO., LTD. IXG-2C7-L
Affected: AIPHONE CO., LTD. IXG-DM7
Affected: AIPHONE CO., LTD. IXG-DM7-HID
Affected: AIPHONE CO., LTD. IXG-DM7-HIDA
Affected: AIPHONE CO., LTD. IXG-DM7-10K
Affected: AIPHONE CO., LTD. IXG-MK
Affected: AIPHONE CO., LTD. IXGW-GW
Affected: AIPHONE CO., LTD. IXGW-TGW
Affected: AIPHONE CO., LTD. IXGW-LC
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-39290?
CVE-2024-39290 has been scored as a medium severity vulnerability.
How to fix CVE-2024-39290?
To fix CVE-2024-39290, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-39290 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-39290 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-39290?
CVE-2024-39290 affects AIPHONE CO., LTD. IX-MV, AIPHONE CO., LTD. IX-MV7-HB, AIPHONE CO., LTD. IX-MV7-HBT, AIPHONE CO., LTD. IX-MV7-HW, AIPHONE CO., LTD. IX-MV7-HWT, AIPHONE CO., LTD. IX-MV7-HW-JP, AIPHONE CO., LTD. IX-MV7-B, AIPHONE CO., LTD. IX-MV7-BT, AIPHONE CO., LTD. IX-MV7-W, AIPHONE CO., LTD. IX-MV7-WT, AIPHONE CO., LTD. IX-DA, AIPHONE CO., LTD. IX-DAU, AIPHONE CO., LTD. IX-DB, AIPHONE CO., LTD. IX-DBT, AIPHONE CO., LTD. IX-EA, AIPHONE CO., LTD. IX-EAT, AIPHONE CO., LTD. IX-EAU, AIPHONE CO., LTD. IX-DV, AIPHONE CO., LTD. IX-DVT, AIPHONE CO., LTD. IX-DVF, AIPHONE CO., LTD. IX-DVF-P, AIPHONE CO., LTD. IX-DVF-L, AIPHONE CO., LTD. IX-DVM, AIPHONE CO., LTD. IX-DU, AIPHONE CO., LTD. IX-DVF-RA, AIPHONE CO., LTD. IX-DVF-2RA, AIPHONE CO., LTD. IX-BA, AIPHONE CO., LTD. IX-BAU, AIPHONE CO., LTD. IX-BB, AIPHONE CO., LTD. IX-BBT, AIPHONE CO., LTD. IX-FA, AIPHONE CO., LTD. IX-SSA, AIPHONE CO., LTD. IX-SS-2G, AIPHONE CO., LTD. IX-SS-2GT, AIPHONE CO., LTD. IX-SS-2G-N, AIPHONE CO., LTD. IX-BU, AIPHONE CO., LTD. IX-SSA-RA, AIPHONE CO., LTD. IX-SSA-2RA, AIPHONE CO., LTD. IX-RS-B, AIPHONE CO., LTD. IX-RS-BT, AIPHONE CO., LTD. IX-RS-W, AIPHONE CO., LTD. IX-RS-WT, AIPHONE CO., LTD. IXW-MA, AIPHONE CO., LTD. IX-SPMIC, AIPHONE CO., LTD. IXG-2C7, AIPHONE CO., LTD. IXG-2C7-L, AIPHONE CO., LTD. IXG-DM7, AIPHONE CO., LTD. IXG-DM7-HID, AIPHONE CO., LTD. IXG-DM7-HIDA, AIPHONE CO., LTD. IXG-DM7-10K, AIPHONE CO., LTD. IXG-MK, AIPHONE CO., LTD. IXGW-GW, AIPHONE CO., LTD. IXGW-TGW, AIPHONE CO., LTD. IXGW-LC.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.