CVE-2024-6080 is a critical unquoted search path vulnerability affecting Intelbras InControl version 2.21.56, specifically within its incontrolWebcam Service component. This flaw, rated 7.8 HIGH on CVSS, requires local access for exploitation and could lead to high impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, and it has garnered minimal community discussion or media coverage. Intelbras plans to release a fix, with an upgrade to version 2.21.58 recommended as a mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.21.56CPE matchmatch criteria | cpe:2.3:o:intelbras:incontrol:2.21.56:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.