{"id":27472,"date":"2024-05-16T12:50:55","date_gmt":"2024-05-16T16:50:55","guid":{"rendered":"https:\/\/avtech.com\/articles\/?p=27472"},"modified":"2024-05-23T15:20:18","modified_gmt":"2024-05-23T19:20:18","slug":"security-advisory-smtp-credentials-pass-back","status":"publish","type":"post","link":"https:\/\/avtech.com\/articles\/27472\/security-advisory-smtp-credentials-pass-back\/","title":{"rendered":"Security Advisory: SMTP Credential Pass-back\u00a0"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">May 16, 2024<\/h5>\n\n\n\n<h4 class=\"wp-block-heading\">CVE-2024-33471<\/h4>\n\n\n\n<p><strong>Impacted Devices and Firmware:<\/strong><\/p>\n\n\n\n<ul>\n<li>Room Alert 4E, firmware 4.4.0 and earlier<\/li>\n\n\n\n<li>Room Alert 3E, firmware 2.4.0 and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 12E, firmware 3.3.0 and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 32E, firmware 3.3.1 and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 3S, firmware&nbsp;1.10.3&nbsp;and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 12S, firmware&nbsp;1.10.3&nbsp;and earlier&nbsp;<\/li>\n\n\n\n<li>Room Alert 32S, firmware&nbsp;1.10.3&nbsp;and earlier&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><strong>Summary:&nbsp;<\/strong><\/p>\n\n\n\n<p>Changing the mail server within the device allows the configured credentials to be sent in plaintext to an attacker via credential pass-back attack.<\/p>\n\n\n\n<p><strong>Description:&nbsp;<\/strong><\/p>\n\n\n\n<p>An individual with administrative access can&nbsp;change the mail server host within the device. An attacker who has obtained administrative access can update the mail server to an attacker controller IP. When the device attempts to authenticate to the mail server, it will pass the previously configured credentials in plaintext to the attacker\u2019s IP.<\/p>\n\n\n\n<p><strong>Recommendation:&nbsp;<\/strong><\/p>\n\n\n\n<p>For users of S-models, upgrade to firmware 1.10.4 or higher which requires SMTP credentials to be re-entered whenever the mail server host is changed. Regardless of the model, AVTECH strongly recommends that users set custom administrative credentials on the device to restrict access to all settings, including SMTP settings. When using E-models, use Room Alert Account or Room Alert Manager, where possible, to send email notifications instead of sending them directly from the device. If the device is not being used to send emails, ensure any SMTP credentials have been removed from the device.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>May 16, 2024 CVE-2024-33471 Impacted Devices and Firmware: Summary:&nbsp; Changing the mail server within the device allows the configured credentials to be sent in plaintext to an attacker via credential pass-back attack. Description:&nbsp; An individual with administrative access can&nbsp;change the mail server host within the device. An attacker who has obtained administrative access can update [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0},"categories":[300],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v15.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/avtech.com\/articles\/27472\/security-advisory-smtp-credentials-pass-back\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Advisory: SMTP Credential Pass-back\u00a0 - AVTECH\" \/>\n<meta property=\"og:description\" content=\"May 16, 2024 CVE-2024-33471 Impacted Devices and Firmware: Summary:&nbsp; Changing the mail server within the device allows the configured credentials to be sent in plaintext to an attacker via credential pass-back attack. Description:&nbsp; An individual with administrative access can&nbsp;change the mail server host within the device. An attacker who has obtained administrative access can update [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/avtech.com\/articles\/27472\/security-advisory-smtp-credentials-pass-back\/\" \/>\n<meta property=\"og:site_name\" content=\"AVTECH\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-16T16:50:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-23T19:20:18+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:creator\" content=\"@AVTECHSoftware\" \/>\n<meta name=\"twitter:site\" content=\"@AVTECHSoftware\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\">\n\t<meta name=\"twitter:data1\" content=\"Allie Wojtanowski\">\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data2\" content=\"1 minute\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/avtech.com\/articles\/#website\",\"url\":\"https:\/\/avtech.com\/articles\/\",\"name\":\"AVTECH\",\"description\":\"Frequently Asked Questions\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/avtech.com\/articles\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/avtech.com\/articles\/27472\/security-advisory-smtp-credentials-pass-back\/#webpage\",\"url\":\"https:\/\/avtech.com\/articles\/27472\/security-advisory-smtp-credentials-pass-back\/\",\"name\":\"Security Advisory: SMTP Credential Pass-back\\u00a0 - AVTECH\",\"isPartOf\":{\"@id\":\"https:\/\/avtech.com\/articles\/#website\"},\"datePublished\":\"2024-05-16T16:50:55+00:00\",\"dateModified\":\"2024-05-23T19:20:18+00:00\",\"author\":{\"@id\":\"https:\/\/avtech.com\/articles\/#\/schema\/person\/2966f1925021087dba64df344049f189\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/avtech.com\/articles\/27472\/security-advisory-smtp-credentials-pass-back\/\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/avtech.com\/articles\/#\/schema\/person\/2966f1925021087dba64df344049f189\",\"name\":\"Allie Wojtanowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/avtech.com\/articles\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/470c9c7fbbd3e0a96d84169645634d04?s=96&d=mm&r=g\",\"caption\":\"Allie Wojtanowski\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/27472"}],"collection":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/comments?post=27472"}],"version-history":[{"count":3,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/27472\/revisions"}],"predecessor-version":[{"id":27494,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/27472\/revisions\/27494"}],"wp:attachment":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/media?parent=27472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/categories?post=27472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/tags?post=27472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}