CVE-2024-43444
Estado: AplazadaAlta (8.2)—
Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled.
This issue affects:
Products based on the ((OTRS)) Community Edition also very likely to be affected
Detalles técnicos trazas, registros y código del informe original
* OTRS from 7.0.X through 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS from 2024.X through 2024.5.X * ((OTRS)) Community Edition: 6.0.x
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-532
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-43444",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-43444",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-26T13:57:06.436622Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@otrs.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@otrs.com",
"affectedData": [
{
"vendor": "OTRS AG",
"modules": [
"Log Module",
"Agent Authentication",
"Customer Authentication"
],
"product": "OTRS",
"versions": [
{
"status": "affected",
"version": "7.0.x",
"versionType": "Patch",
"lessThanOrEqual": "7.0.50"
},
{
"status": "affected",
"version": "8.0.x"
},
{
"status": "affected",
"version": "2023.x"
},
{
"status": "affected",
"version": "2024.x",
"versionType": "Patch",
"lessThanOrEqual": "2024.5.x"
}
],
"defaultStatus": "affected"
},
{
"vendor": "OTRS AG",
"modules": [
"Log Module",
"Agent Authentication",
"Customer Authentication"
],
"product": "((OTRS)) Community Edition",
"versions": [
{
"status": "affected",
"version": "6.0.x"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*"
],
"vendor": "otrs",
"product": "otrs",
"versions": [
{
"status": "affected",
"version": "7.0.0",
"versionType": "custom",
"lessThanOrEqual": "7.0.50"
},
{
"status": "affected",
"version": "8.0.0"
},
{
"status": "affected",
"version": "2023.0"
},
{
"status": "affected",
"version": "2024.0",
"versionType": "custom",
"lessThanOrEqual": "2024.5.0"
}
],
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*"
],
"vendor": "otrs",
"product": "otrs",
"versions": [
{
"status": "affected",
"version": "6.0.0"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-08-26T09:15:04.760",
"references": [
{
"url": "https://otrs.com/release-notes/otrs-security-advisory-2024-12/",
"source": "security@otrs.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security@otrs.com",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled.\n\nThis issue affects: \n\n * OTRS from 7.0.X through 7.0.50\n * OTRS 8.0.X\n * OTRS 2023.X\n * OTRS from 2024.X through 2024.5.X\n * ((OTRS)) Community Edition: 6.0.x\n\nProducts based on the ((OTRS)) Community Edition also very likely to be affected"
},
{
"lang": "es",
"value": "Las contraseñas de agentes y clientes se muestran en texto plano en el módulo de registro de administración de OTRS si ciertas configuraciones relacionadas con las fuentes de autenticación coinciden y se ha habilitado la depuración para el backend de autenticación. Este problema afecta a: * OTRS desde 7.0.X hasta 7.0.50 * OTRS 8.0.X * OTRS 2023.X * OTRS desde 2024.X hasta 2024.5.X * ((OTRS)) Edición comunitaria: 6.0.x Productos basados en ((OTRS)) Community Edition también es muy probable que se vea afectada"
}
],
"lastModified": "2026-06-17T07:51:03.450",
"sourceIdentifier": "security@otrs.com"
}