An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access the administration panel
References
| Link | Resource |
|---|---|
| https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24721 | Third Party Advisory |
| https://excellium-services.com/cert-xlm-advisory/CVE-2024-24721 | Not Applicable |
| https://excellium-services.com/cert-xlm-advisory/CVE-2024-24721 | Not Applicable |
Configurations
History
No history.
Information
Published : 2024-02-27 00:15
Updated : 2025-09-18 16:26
NVD link : CVE-2024-24721
Mitre link : CVE-2024-24721
CVE.ORG link : CVE-2024-24721
JSON object : View
Products Affected
innovaphone
- innovaphone_pbx
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
