AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)The advisory applies only to The RCDevs OpenOTP SMS plugin. The RCDevs OpenOTP SMS connector shipped with SMSEagle did not validate the TLS certificate of the remote endpoint, and transmitted the connection credentials and the message content as parameters in the request URL. An attacker in a privileged network position could intercept or tamper with this traffic.
Upgrade to latest version of RCDevs OpenOTP SMS integration connector. The fix enforces TLS certificate validation and stops transmitting credentials in the request URL.
Until the upgrade, restrict the connector to trusted network paths and ensure the endpoint uses a valid, verifiable TLS certificate.
We thank Marish Vhia Pasco for reporting this issue in line with our responsible disclosure policy.
SMSEagle continuously monitors and reports cybersecurity threats, enabling our customers to proactively take necessary mitigation steps to maintain the security of their devices. To assist you in managing and mitigating security risks SMSEagle offers product advisories.