CVE-2024-9324 is a critical code injection vulnerability affecting Intelbras InControl versions up to 2.21.57, specifically within the /v1/operador/ functionality of the Relatório de Operadores Page. This flaw allows remote attackers to execute arbitrary code by manipulating argument fields. With a CVSS score of 8.8 (High), it poses a significant risk of complete compromise (confidentiality, integrity, availability). While a public exploit has been disclosed, there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion. A fix is available in version 2.21.58, released on September 20, 2024.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.21.58CPE matchmatch criteria | cpe:2.3:a:intelbras:incontrol_web:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.