{"id":27443,"date":"2024-05-16T12:46:56","date_gmt":"2024-05-16T16:46:56","guid":{"rendered":"https:\/\/avtech.com\/articles\/?p=27443"},"modified":"2024-05-23T15:20:44","modified_gmt":"2024-05-23T19:20:44","slug":"security-advisory-smtp-password-disclosure-in-dom","status":"publish","type":"post","link":"https:\/\/avtech.com\/articles\/27443\/security-advisory-smtp-password-disclosure-in-dom\/","title":{"rendered":"Security Advisory: SMTP Password Disclosure in DOM"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">May 16, 2024<\/h5>\n\n\n\n<h4 class=\"wp-block-heading\">CVE-2024-33470<\/h4>\n\n\n\n<p><strong>Impacted Devices and Firmware:<\/strong><\/p>\n\n\n\n<ul>\n<li>Room Alert 4E, firmware 4.4.0 and earlier<\/li>\n\n\n\n<li>Room Alert 3E, firmware 2.4.0 and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 12E, firmware 3.3.0 and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 32E, firmware 3.3.1 and earlier<\/li>\n<\/ul>\n\n\n\n<p><strong>Summary:&nbsp;<\/strong><\/p>\n\n\n\n<p>The SMTP password for a previously saved set of credentials is disclosed by the device to an administrator.&nbsp;<\/p>\n\n\n\n<p><strong>Description:&nbsp;<\/strong><\/p>\n\n\n\n<p>When an administrator authenticates with the device and browses the settings pages, the SMTP password is loaded from the device and presented in the DOM in plaintext. When settings are saved, the SMTP credentials are sent back to the device in plain text. This allows an actor with administrative access to the device to obtain the SMTP credentials previously stored in the device&#8217;s settings.\u00a0<\/p>\n\n\n\n<p><strong>Recommendation:&nbsp;<\/strong><\/p>\n\n\n\n<p>For best security, upgrade from legacy E-model devices to S-models which do not have this vulnerability. Regardless of the model, AVTECH strongly recommends that users set custom administrative credentials on the device to restrict access to all settings, including SMTP credentials. When using E-models, use Room Alert Account or Room Alert Manager, where possible, to send email notifications instead of sending them directly from the device. If the device is not being used to send emails, ensure any SMTP credentials have been removed from the device. &nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>May 16, 2024 CVE-2024-33470 Impacted Devices and Firmware: Summary:&nbsp; The SMTP password for a previously saved set of credentials is disclosed by the device to an administrator.&nbsp; Description:&nbsp; When an administrator authenticates with the device and browses the settings pages, the SMTP password is loaded from the device and presented in the DOM in plaintext. [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0},"categories":[300],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v15.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/avtech.com\/articles\/27443\/security-advisory-smtp-password-disclosure-in-dom\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Advisory: SMTP Password Disclosure in DOM - AVTECH\" \/>\n<meta property=\"og:description\" content=\"May 16, 2024 CVE-2024-33470 Impacted Devices and Firmware: Summary:&nbsp; The SMTP password for a previously saved set of credentials is disclosed by the device to an administrator.&nbsp; Description:&nbsp; When an administrator authenticates with the device and browses the settings pages, the SMTP password is loaded from the device and presented in the DOM in plaintext. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/avtech.com\/articles\/27443\/security-advisory-smtp-password-disclosure-in-dom\/\" \/>\n<meta property=\"og:site_name\" content=\"AVTECH\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-16T16:46:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-23T19:20:44+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:creator\" content=\"@AVTECHSoftware\" \/>\n<meta name=\"twitter:site\" content=\"@AVTECHSoftware\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\">\n\t<meta name=\"twitter:data1\" content=\"Allie Wojtanowski\">\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data2\" content=\"1 minute\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/avtech.com\/articles\/#website\",\"url\":\"https:\/\/avtech.com\/articles\/\",\"name\":\"AVTECH\",\"description\":\"Frequently Asked Questions\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/avtech.com\/articles\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/avtech.com\/articles\/27443\/security-advisory-smtp-password-disclosure-in-dom\/#webpage\",\"url\":\"https:\/\/avtech.com\/articles\/27443\/security-advisory-smtp-password-disclosure-in-dom\/\",\"name\":\"Security Advisory: SMTP Password Disclosure in DOM - AVTECH\",\"isPartOf\":{\"@id\":\"https:\/\/avtech.com\/articles\/#website\"},\"datePublished\":\"2024-05-16T16:46:56+00:00\",\"dateModified\":\"2024-05-23T19:20:44+00:00\",\"author\":{\"@id\":\"https:\/\/avtech.com\/articles\/#\/schema\/person\/2966f1925021087dba64df344049f189\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/avtech.com\/articles\/27443\/security-advisory-smtp-password-disclosure-in-dom\/\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/avtech.com\/articles\/#\/schema\/person\/2966f1925021087dba64df344049f189\",\"name\":\"Allie Wojtanowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/avtech.com\/articles\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/470c9c7fbbd3e0a96d84169645634d04?s=96&d=mm&r=g\",\"caption\":\"Allie Wojtanowski\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/27443"}],"collection":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/comments?post=27443"}],"version-history":[{"count":13,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/27443\/revisions"}],"predecessor-version":[{"id":27495,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/27443\/revisions\/27495"}],"wp:attachment":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/media?parent=27443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/categories?post=27443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/tags?post=27443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}