PT-2024-24147 · Intelbras · Intelbras Hdcvi 1008+5

Netsecfish

·

Published

2024-04-02

·

Updated

2024-08-01

·

CVE-2024-3160

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intelbras MHDX 1004 versions up to 20240401 Intelbras MHDX 1008 versions up to 20240401 Intelbras MHDX 1016 versions up to 20240401 Intelbras MHDX 5016 versions up to 20240401 Intelbras HDCVI 1008 versions up to 20240401 Intelbras HDCVI 1016 versions up to 20240401
Description A vulnerability was found in the HTTP GET Request Handler component, affecting an unknown part of the file /cap.js. The manipulation leads to information disclosure and can be initiated remotely. The real existence of this vulnerability is still doubted. The vendor explains that they do not classify the information shown as sensitive and therefore there is no vulnerability which is about to harm the user.
Recommendations For Intelbras MHDX 1004 versions up to 20240401, review logs and apply strict firewall rules to minimize the risk of exploitation. For Intelbras MHDX 1008 versions up to 20240401, review logs and apply strict firewall rules to minimize the risk of exploitation. For Intelbras MHDX 1016 versions up to 20240401, review logs and apply strict firewall rules to minimize the risk of exploitation. For Intelbras MHDX 5016 versions up to 20240401, review logs and apply strict firewall rules to minimize the risk of exploitation. For Intelbras HDCVI 1008 versions up to 20240401, review logs and apply strict firewall rules to minimize the risk of exploitation. For Intelbras HDCVI 1016 versions up to 20240401, review logs and apply strict firewall rules to minimize the risk of exploitation. As a temporary workaround, consider restricting access to the /cap.js file until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3160

Affected Products

Intelbras Hdcvi 1008
Intelbras Hdcvi 1016
Intelbras Mhdx 1004
Intelbras Mhdx 1008
Intelbras Mhdx 1016
Intelbras Mhdx 5016