Impact
SmartIT Desktop Manager includes hard‑coded SFTP credentials that can be read from the source code by unauthenticated remote attackers. This flaw enables them to access the file system of the host machine, exposing sensitive files and potentially additional system resources. The weakness is categorized as CWE‑798 and has a CVSS score of 6.9, indicating a moderate severity risk for confidentiality and integrity.
Affected Systems
The vulnerability affects Lightstar’s SmartIT Desktop Manager. Users who have not yet upgraded to version 11 or later are impacted; the official fix requires installing that release or newer.
Risk and Exploitability
Because the credentials are embedded in the code, an attacker can exploit the flaw without needing prior authentication or complex preparation. The EPSS score is not available; however, the moderate CVSS score suggests that the vulnerability could be useful in targeted attacks. The flaw is not listed in CISA’s KEV catalog, but its straightforward exploitation path makes it a priority to remediate.
OpenCVE Enrichment