PT-2024-39574 · Intelbras · Intelbras Incontrol

J369

·

Published

2024-09-29

·

Updated

2024-11-04

·

CVE-2024-9325

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intelbras InControl versions up to 2.21.56
Description A critical vulnerability has been found in Intelbras InControl, affecting an unknown part of the file C:Program Files (x86)IntelbrasIncontrol Clienteincontrol webcamincontrol-service-watchdog.exe. The manipulation leads to an unquoted search path, allowing an attack to be launched on the local host.
Recommendations For versions up to 2.21.56, upgrade to version 2.21.58 to address this issue. As a temporary workaround, consider restricting access to the affected file incontrol-service-watchdog.exe until a patch is available.

Exploit

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2024-9325

Affected Products

Intelbras Incontrol