Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.
Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.
| Vendor | Product | Versions |
|---|---|---|
| AIPHONE CO., LTD. | IX | MV — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-HB — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-HBT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-HW — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-HWT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-HW-JP — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-B — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-BT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-W — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | MV7-WT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | DA — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | DAU — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | DB — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | DBT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | EA — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | EAT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | EAU — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | DV — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVT — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVF — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVF-P — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVF-L — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVM — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | DU — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVF-RA — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | DVF-2RA — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | BA — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | BAU — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | BB — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | BBT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | FA — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | SSA — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | SS-2G — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | SS-2GT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | SS-2G-N — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | BU — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | SSA-RA — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | SSA-2RA — firmware Ver.7.11 and earlier |
| AIPHONE CO., LTD. | IX | RS-B — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | RS-BT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | RS-W — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | RS-WT — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IXW | MA — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IX | SPMIC — firmware Ver.7.10 and earlier |
| AIPHONE CO., LTD. | IXG | 2C7 — firmware Ver.3.01 and earlier |
| AIPHONE CO., LTD. | IXG | 2C7-L — firmware Ver.3.01 and earlier |
| AIPHONE CO., LTD. | IXG | DM7 — firmware Ver.3.00 and earlier |
| AIPHONE CO., LTD. | IXG | DM7-HID — firmware Ver.3.00 and earlier |
| AIPHONE CO., LTD. | IXG | DM7-HIDA — firmware Ver.3.00 and earlier |
| AIPHONE CO., LTD. | IXG | DM7-10K — firmware Ver.3.00 and earlier |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.