PT-2026-23460 · Unknown · Rustdesk Client
Erez Kalman
·
Publicado
2026-03-05
·
Atualizado
2026-03-05
·
CVE-2026-30795
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk Client versions through 1.4.5
Description
A cleartext transmission of sensitive information issue exists in RustDesk Client on Windows, MacOS, Linux, iOS, and Android, specifically within the Heartbeat sync loop modules. This allows for potential sniffing attacks. The issue is related to the construction of Heartbeat JSON payloads, including preset address book passwords, within the
src/hbbs http/sync.Rs file and the Heartbeat routine.Recommendations
Update RustDesk Client to a version later than 1.4.5.
Exploit
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rustdesk Client