CVE-2024-7421

Sept. 25, 2024, 4:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Devolutions Remote Desktop Manager

  • 2024.2.20.0
  • earlier

Source

security@devolutions.net

Tags

CVE-2024-7421 details

Published : Sept. 25, 2024, 4:15 p.m.
Last Modified : Sept. 25, 2024, 4:15 p.m.

Description

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-532 Insertion of Sensitive Information into Log File Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

References

URL Source
https://devolutions.net/security/advisories/DEVO-2024-0014 security@devolutions.net
This website uses the NVD API, but is not approved or certified by it.