Information Exposure in Devolutions Remote Desktop Manager on Windows
CVE-2024-7421

5.5MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2024

What is CVE-2024-7421?

An information exposure vulnerability in Devolutions Remote Desktop Manager versions 2024.2.20.0 and earlier allows local attackers to gain unauthorized access to sensitive session credentials. This occurs when passwords are included in command-line arguments that are logged when launching WinSCP sessions. Attackers with access to the system logs can potentially extract these passwords, leading to unauthorized access and compromise of remote transactions. It is crucial for users to be aware of this vulnerability and secure their logs to prevent data breaches.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.