CVE-2024-3160 is a disputed information disclosure vulnerability affecting several Intelbras MHDX and HDCVI DVR models up to the 20240401 firmware. It involves an unknown part of the /cap.js file within the HTTP GET Request Handler, potentially allowing remote attackers to access sensitive information. Rated Medium (CVSS 5.3), this vulnerability has a low impact on confidentiality and requires no user interaction or privileges. While the exploit has been publicly disclosed, its real existence is doubted by the vendor, who states the exposed information is not sensitive. There is no evidence of active exploitation, and it lacks exploit intelligence in common databases and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Intelbras | HDCVI 1008 | 20240401CNA affected | |
| Intelbras | HDCVI 1016 | 20240401CNA affected | |
| Intelbras | MHDX 1004 | 20240401CNA affected | |
| Intelbras | MHDX 1008 | 20240401CNA affected | |
| Intelbras | MHDX 1016 | 20240401CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.