MIPC Product Security Update Advisory (CVE-2024-39091)

Overview

 

An update has been released to address vulnerabilities in MIPC products. Users of the affected versions are advised to update to the latest version.

 

Affected Products

CVE-2024-39091

  • Annke Crater 2 camera firmware versions: ~ 5.4.1.221222153318 (included)

 

 

Resolved Vulnerabilities

OS command injection vulnerability in the ccm_debug component of the MIPC camera firmware allows attackers within the same network to execute arbitrary code via a crafted HTML request (CVE-2024-39091)

 

Vulnerability Patches

The following product-specific Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2024-39091

  • MIPC Camera Framework version: 5.4.1.240424171021

     

References

[1] CVE-2024-39091 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-39091

[2] MIPC Camera Firmware Vulnerability

https://joerngermany.github.io/mipc_vulnerability/