An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
History

Tue, 01 Oct 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
CPEs cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
Vendors & Products Devolutions
Devolutions remote Desktop Manager
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 25 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Sep 2024 15:15:00 +0000

Type Values Removed Values Added
Description An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
Weaknesses CWE-532
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2024-09-25T15:12:54.854Z

Updated: 2024-09-25T15:36:09.369Z

Reserved: 2024-08-02T13:55:12.876Z

Link: CVE-2024-7421

cve-icon Vulnrichment

Updated: 2024-09-25T15:36:01.013Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-25T16:15:11.187

Modified: 2024-10-01T18:36:59.117

Link: CVE-2024-7421

cve-icon Redhat

No data.