Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2024-0014

Remote Desktop Manager Windows is affected by a vulnerability.

Affected Products

Remote Desktop Manager
2024.2.20 and earlier

Change Log

25/09/2024 - Initial publication

Medium - CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Information exposure in windows Logs via WinSCP session

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions

Affected Products

CVE(s)

CVE-2024-7421

Remediation and Workarounds

Upgrade to Remote Desktop Manager 2024.3.10 or higher