Plaintext Credentials Exposure in SMTP Email Settings
CVE-2024-33470

4.9MEDIUM

Key Information:

Vendor

AVTECH

Vendor
CVE Published:
24 May 2024

What is CVE-2024-33470?

An identified vulnerability in the SMTP Email Settings of AVTECH Room Alert 4E version 4.4.0 allows unauthorized attackers to access sensitive credentials stored in plaintext. This vulnerability results from a passback attack technique, which poses significant risks to users of outdated devices. It is essential to note that this issue specifically impacts products that no longer receive support from the vendor, rendering them more susceptible to exploitation. Companies using the affected version are advised to consider mitigation measures or an upgrade to maintain security integrity.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.