Security & Compliance
DEVO-2024-0014
Summary
Remote Desktop Manager Windows is affected by a vulnerability.
Affected Products
Remote Desktop Manager 2024.2.20 and earlier
Change Log
25/09/2024 - Initial publication
Severity
Medium
Product
Remote Desktop Manager Windows
Fix Version
2024.3.10
information exposure in windows Logs via WinSCP session
Description
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
Remediation and Workarounds
Upgrade to Remote Desktop Manager 2024.3.10 or higher
Severity
Medium - CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
Remote Desktop Manager 2024.2.20 and earlier
CVE(s)
CVE-2024-7421