OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.
CVE ID: CVE-2024-31408
CVSS Base Severity: HIGH
CVSS Base Score: 8.0
Vendor: AIPHONE CO., LTD.
Product: IX-MV
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 19.35% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)