PT-2024-25276 · Avtech · Avtech Room Alert 4E

Published

2024-05-24

·

Updated

2024-11-13

·

CVE-2024-33471

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVTECH Room Alert 4E version 4.4.0
Description An issue in the Sensor Settings allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request to an unspecified API endpoint. This issue only affects products that are no longer supported by the maintainer.
Recommendations For AVTECH Room Alert 4E version 4.4.0, as a temporary workaround, consider restricting access to the Sensor Settings until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-33471

Affected Products

Avtech Room Alert 4E