PT-2024-17783 · Intelbras · Intelbras Vip S4020 G3+3

Netsecfish

·

Published

2024-12-22

·

Updated

2024-12-24

·

CVE-2024-12896

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intelbras VIP S3020 G2 versions up to 20241222 Intelbras VIP S4020 G2 versions up to 20241222 Intelbras VIP S4020 G3 versions up to 20241222 Intelbras VIP S4320 G2 versions up to 20241222
Description A vulnerability was found in the Web Interface component of Intelbras IP cameras, specifically affecting some unknown functionality of the file /web caps/webCapsConfig. The manipulation of this functionality leads to information disclosure. The attack can be launched remotely. The vendor assesses that the disclosed information is not sensitive and poses no risk to the user.
Recommendations For Intelbras VIP S3020 G2 versions up to 20241222, restrict access to the /web caps/webCapsConfig file to minimize the risk of exploitation. For Intelbras VIP S4020 G2 versions up to 20241222, consider disabling the Web Interface component until a patch is available. For Intelbras VIP S4020 G3 versions up to 20241222, avoid using the Web Interface component until the issue is resolved. For Intelbras VIP S4320 G2 versions up to 20241222, limit remote access to the Web Interface component to prevent potential attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-12896

Affected Products

Intelbras Vip S3020 G2
Intelbras Vip S4020 G2
Intelbras Vip S4020 G3
Intelbras Vip S4320 G2