CVE-2024-39290: Aiphone Co., Ltd Ix-BA

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.

Affected products

Published 2024-11-22. Last modified 2026-06-17.