An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://devolutions.net/security/advisories/DEVO-2024-0014 | vendor advisory |