CVE-2024-33471: High severity AVTECH Room Alert 4E vulnerability
An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33471?
CVE-2024-33471 is classified as a high-severity vulnerability due to the potential exposure of sensitive SMTP credentials.
How do I fix CVE-2024-33471?
To mitigate CVE-2024-33471, immediately discontinue use of AVTECH Room Alert 4E v4.4.0 and move to a supported product version.
What kind of access does CVE-2024-33471 allow attackers?
CVE-2024-33471 allows attackers to gain access to SMTP credentials in plaintext through specially crafted AJAX requests.
Is my AVTECH Room Alert 4E device affected by CVE-2024-33471?
If you are using AVTECH Room Alert 4E v4.4.0, your device is affected by CVE-2024-33471.
Why is CVE-2024-33471 a concern for users of unsupported products?
CVE-2024-33471 is particularly concerning for users of unsupported products as they do not receive security updates, leaving them vulnerable to exploitation.