CVE-2024-58337

7.5

Akuvox · Smart Intercom and Smart Doorphone

Akuvox intercom and doorphone devices contain an improper access control vulnerability allowing authenticated users to modify sensitive API settings and escalate privileges.

Executive summary

An improper access control flaw in various Akuvox Smart Intercom and Doorphone models allows authenticated users to gain unauthorized administrative access and modify critical system configurations.

Vulnerability

This vulnerability, identified as CWE-862, stems from missing authorization checks within the API. An attacker with standard user privileges can interact with restricted endpoints to alter API access settings, effectively bypassing intended security controls to perform administrative actions.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it allows for unauthorized administrative control over intercom and doorphone infrastructure. Given the CVSS score of 7.5, this high-severity flaw could lead to the compromise of physical access security, unauthorized monitoring, or the manipulation of communication systems, resulting in significant reputational damage and potential physical security breaches.

Remediation

Immediate Action: Contact the vendor or consult the official Akuvox support portal to verify the availability of firmware updates that address this access control deficiency.

Proactive Monitoring: Review system audit logs for anomalous API requests, particularly those originating from accounts with standard user privileges that attempt to access administrative configuration endpoints.

Compensating Controls: Restrict network access to the management interfaces of these devices to trusted management subnets and employ a Web Application Firewall (WAF) to filter unauthorized API calls.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the existence of a proof-of-concept, organizations utilizing the affected Akuvox hardware must prioritize this issue. Administrators should immediately audit user access levels and restrict administrative API access to hardened, internal networks until a formal firmware patch is applied to remediate the underlying authorization logic.

More Akuvox CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.