CVE-2024-39220
EUVD-2024-3787003.07.2024, 15:15
BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD before firmware v3.9.2 allows authenticated attackers to read SIP account passwords via a crafted GET request.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| bas-ip | av-01d | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-01md | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-01mfd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-01ed | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-01kd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-01bd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-02d | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-02ide | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-02idr | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-02ipd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-02fde | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-02fdr | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-03d | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-03bd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-04afd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-04asd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-04fd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-04sd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-05fd | 𝑥 < 3.9.2 | ADP |
| bas-ip | av-05sd | 𝑥 < 3.9.2 | ADP |
| bas-ip | aa-07bd | 𝑥 < 3.9.2 | ADP |
| bas-ip | aa-07bdi | 𝑥 < 3.9.2 | ADP |
| bas-ip | ba-04bd | 𝑥 < 3.9.2 | ADP |
| bas-ip | ba-04md | 𝑥 < 3.9.2 | ADP |
| bas-ip | ba-08bd | 𝑥 < 3.9.2 | ADP |
| bas-ip | ba-08md | 𝑥 < 3.9.2 | ADP |
| bas-ip | ba-12bd | 𝑥 < 3.9.2 | ADP |
| bas-ip | ba-12md | 𝑥 < 3.9.2 | ADP |
| bas-ip | cr-02bd | 𝑥 < 3.9.2 | ADP |
Common Weakness Enumeration