The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding a critical vulnerability in Avtech Security cameras. Tracked as CVE-2024-7029, this flaw affects Avtech AVM1203 IP cameras running firmware versions FullImg-1023-1007-1011-1009 and earlier, and potentially other Avtech cameras and NVRs. The vulnerability allows remote command injection over the network without authentication, making it highly exploitable. CISA Confirms Active Exploitation of Vulnerability. Unfortunately, Avtech has not responded to CISA’s efforts to address the issue, suggesting that the vulnerability remains unpatched. CISA’s awareness of this vulnerability stems from a report by Akamai, which was corroborated by an anonymous third-party organization that identified the affected products and firmware versions. While no public reports currently describe attacks exploiting CVE-2024-7029, it is important to note that Avtech cameras have previously been targeted by IoT botnets like Hide ‘N Seek and Mirai variants. The affected Avtech products are used globally across critical sectors, including commercial facilities, healthcare, financial services, and transportation. As of now, CISA has not included CVE-2024-7029 in its Known Exploited Vulnerabilities Catalog. Users of Avtech products are advised to monitor for any unusual activity and consider alternative security measures until a patch is available.
According to cybersecurity experts, there has been a significant increase in ransomware attacks powered by artificial intelligence technology. In the past several months, 7,831 vic...
A new online scam is tricking users through fake CAPTCHA pages and causing unexpected charges on their mobile bills. Normally, CAPTCHA is used to check if a user is human, like sel...
The Wireshark Foundation has released version 4.6.5 of Wireshark to address a significant number of security vulnerabilities impacting its widely used network analysis tool. This u...