PT-2024-6667 · Devolutions · Devolutions Remote Desktop Manager

Published

2024-08-02

·

Updated

2024-10-01

·

CVE-2024-7421

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Devolutions Remote Desktop Manager versions 2024.2.20.0 and earlier
Description: The issue is related to an information exposure that allows local attackers with access to system logs to obtain session credentials. This occurs via passwords included in command-line arguments when launching WinSCP sessions. The vulnerability is associated with the Command-Line Argument Handler component, which can lead to the disclosure of user credentials through log files.
Recommendations: For Devolutions Remote Desktop Manager versions 2024.2.20.0 and earlier, consider disabling the launch of WinSCP sessions until a patch is available to prevent the exposure of session credentials. Restrict access to system logs to minimize the risk of exploitation. As a temporary workaround, avoid using command-line arguments that include passwords when launching WinSCP sessions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07869
CVE-2024-7421

Affected Products

Devolutions Remote Desktop Manager