CVE-2024-12984

MEDIUM

Amcrest <20241211 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic has been found in Amcrest IP2M-841B, IP2M-841W, IPC-IP2M-841B, IPC-IP3M-943B, IPC-IP3M-943S, IPC-IP3M-HX2B and IPC-IPM-721S up to 20241211. This affects an unknown part of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.289377
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.289377
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.461109

Scores

CVSS v3 5.3
EPSS 0.0058
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (7)
Amcrest/IP2M-841B 20241211
Amcrest/IP2M-841W 20241211
Amcrest/IPC-IP2M-841B 20241211
Amcrest/IPC-IP3M-943B 20241211
Amcrest/IPC-IP3M-943S 20241211
Amcrest/IPC-IP3M-HX2B 20241211
Amcrest/IPC-IPM-721S 20241211
Published Dec 27, 2024
Tracked Since Feb 18, 2026