CRITICAL🇵🇱 Wersja polska

CVE-2024-38883

CVSS 9.1v3.1pub. 2024-08-02upd. 2026-07-05

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

🤖 AI Analysis
How it works

During network connection establishment, the Caterease application allows negotiation of less secure encryption algorithms (CWE-757: Selection of Less-Secure Algorithm During Negotiation). An attacker can force both sides of the communication to agree on a weaker protocol or cipher, resulting in a reduction in the actual level of transmission protection. This makes it possible to intercept or manipulate data transmitted between the client and server.

Impact

An attacker can gain unauthorized access to sensitive data transmitted by the application and potentially modify it, which threatens both the confidentiality and integrity of communications.

Mitigation & patch

Apply patches available from the vendor according to the references. It is also recommended to configure the network environment to enforce the use of only strong encryption algorithms on the server side, and to monitor network traffic for attempts to negotiate weaker ciphers.

Who is affected

Horizon Business Services Inc. Caterease versions from 16.0.1.1663 to 24.0.1.2405 inclusive and potentially newer versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Horizoncloud Caterease

    APP
    Horizoncloud
    16.0.1.1663 – 24.0.1.2405
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38886CRITICAL9.8PL ✓same product

Traffic Injection w Horizoncloud Caterease – brak weryfikacji źródła komunikacji

CVE-2024-38887CRITICAL9.8PL ✓same product

Command Injection w Horizoncloud Caterease — zdalne przejęcie systemu OS

CVE-2024-38889CRITICAL9.8PL ✓same product

SQL Injection w Horizoncloud Caterease — zdalne wykonanie zapytań

CVE-2024-38882CRITICAL9.8PL ✓same product

SQL Injection umożliwiający command injection w Horizoncloud Caterease

CVE-2024-38891HIGH7.5same product

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versio...