CVE-2024-24720

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:innovaphone:innovaphone_pbx:*:*:*:*:*:*:*:*
cpe:2.3:a:innovaphone:innovaphone_pbx:14r1:*:*:*:*:*:*:*

History

18 Sep 2025, 16:27

Type Values Removed Values Added
References () https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24720 - () https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24720 - Third Party Advisory
References () https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720 - () https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720 - Not Applicable
References () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate - () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate - Release Notes
First Time Innovaphone innovaphone Pbx
Innovaphone
CPE cpe:2.3:a:innovaphone:innovaphone_pbx:14r1:*:*:*:*:*:*:*
cpe:2.3:a:innovaphone:innovaphone_pbx:*:*:*:*:*:*:*:*

30 May 2025, 16:15

Type Values Removed Values Added
References
  • () https://cds.thalesgroup.com/en/tcs-cert/CVE-2024-24720 -

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720 - () https://excellium-services.com/cert-xlm-advisory/CVE-2024-24720 -
References () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate - () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate -

14 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

02 May 2024, 17:15

Type Values Removed Values Added
Summary (en) An issue was discovered on Innovaphone PBX before 14r1 devices. It provides different responses to incoming requests in a way that reveals information to an attacker. (en) An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
References
  • () https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Security#156999_-_App_Users:_Prevent_account_enumerate -

27 Feb 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-27 01:15

Updated : 2025-09-18 16:27


NVD link : CVE-2024-24720

Mitre link : CVE-2024-24720

CVE.ORG link : CVE-2024-24720


JSON object : View

Products Affected

innovaphone

  • innovaphone_pbx
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor