CVE-2024-34885: Medium severity 1C-Bitrix Bitrix24 vulnerability
Published Nov 4, 2024
·Updated
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.
Affected Software
2 affected components
1C-Bitrix Bitrix24
Bitrix24 Bitrix24=23.300.100
Event History
Nov 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34885?
CVE-2024-34885 has a high severity rating due to its potential for exposing sensitive SMTP credentials.
2
How do I fix CVE-2024-34885?
To fix CVE-2024-34885, ensure that SMTP server settings are properly secured and configured to prevent unauthorized access.
3
What applications are affected by CVE-2024-34885?
CVE-2024-34885 affects the 1C-Bitrix Bitrix24 version 23.300.100.
4
Can CVE-2024-34885 be exploited remotely?
Yes, CVE-2024-34885 can be exploited remotely by attackers who can send HTTP GET requests to the vulnerable server.
5
What are the implications of CVE-2024-34885?
The implications of CVE-2024-34885 include the risk of unauthorized access to SMTP accounts, potentially compromising email communications.