PT-2024-25275 · Avtech · Avtech Room Alert 4E

Published

2024-05-24

·

Updated

2024-10-31

·

CVE-2024-33470

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AVTECH Room Alert 4E version 4.4.0
Description An issue in the SMTP Email Settings allows attackers to gain access to credentials in plaintext via a passback attack. This issue only affects products that are no longer supported by the maintainer.
Recommendations For AVTECH Room Alert 4E version 4.4.0, as a temporary workaround, consider disabling the SMTP Email Settings until a patch is available, but since the product is no longer supported, this might be the only available mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-33470

Affected Products

Avtech Room Alert 4E