Security & Compliance

DEVO-2024-0014

Summary

Remote Desktop Manager Windows is affected by a vulnerability.

Affected Products

Remote Desktop Manager 2024.2.20 and earlier

Change Log

25/09/2024 - Initial publication

Severity

Medium

Product

Remote Desktop Manager Windows

Fix Version

2024.3.10

information exposure in windows Logs via WinSCP session

Description

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions

Remediation and Workarounds

Upgrade to Remote Desktop Manager 2024.3.10 or higher

Severity

Medium - CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

Remote Desktop Manager 2024.2.20 and earlier

CVE(s)

CVE-2024-7421