Intelbras Vulnerabilities and Affected Products
Vulnerabilities associated with VIP S4320 G2.
Products
Clear product- InControl8 vulnerabilities
- VIP S3020 G22 vulnerabilities
- VIP S4020 G22 vulnerabilities
- VIP S4020 G32 vulnerabilities
- VIP S4320 G22 vulnerabilities
- HDCVI 10081 vulnerability
- HDCVI 10161 vulnerability
- hdcvi_1008_firmware1 vulnerability
- hdcvi_1016_firmware1 vulnerability
- ICIP1 vulnerability
- Intelbras Router RF 301K1 vulnerability
- iNVU 7016 FT1 vulnerability
- MHDX 10041 vulnerability
- MHDX 10081 vulnerability
- MHDX 10161 vulnerability
- MHDX 50161 vulnerability
- mhdx_1004_firmware1 vulnerability
- mhdx_1008_firmware1 vulnerability
- mhdx_1016_firmware1 vulnerability
- mhdx_5016_firmware1 vulnerability
- RF 301K1 vulnerability
- RX 15001 vulnerability
- sg_2404_mr1 vulnerability
- sg_2404_mr_firmware1 vulnerability
- Telefone IP TIP 2001 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-12897MEDIUM | Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversalA vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS5.3v4.0 | EPSS0.472% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12896MEDIUM | Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosureA vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as problematic. Affected by this issue is some unknown functionality of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor assesses that "the information disclosed in the URL is not sensitive or pose… | CVSS6.9v4.0 | EPSS0.472% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |