An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.
During network connection establishment, the Caterease application allows negotiation of less secure encryption algorithms (CWE-757: Selection of Less-Secure Algorithm During Negotiation). An attacker can force both sides of the communication to agree on a weaker protocol or cipher, resulting in a reduction in the actual level of transmission protection. This makes it possible to intercept or manipulate data transmitted between the client and server.
An attacker can gain unauthorized access to sensitive data transmitted by the application and potentially modify it, which threatens both the confidentiality and integrity of communications.
Apply patches available from the vendor according to the references. It is also recommended to configure the network environment to enforce the use of only strong encryption algorithms on the server side, and to monitor network traffic for attempts to negotiate weaker ciphers.
Horizon Business Services Inc. Caterease versions from 16.0.1.1663 to 24.0.1.2405 inclusive and potentially newer versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHorizoncloud Caterease
APPHorizoncloud16.0.1.1663 – 24.0.1.2405
Related vulnerabilities
Traffic Injection w Horizoncloud Caterease – brak weryfikacji źródła komunikacji
Command Injection w Horizoncloud Caterease — zdalne przejęcie systemu OS
SQL Injection w Horizoncloud Caterease — zdalne wykonanie zapytań
SQL Injection umożliwiający command injection w Horizoncloud Caterease
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versio...