CVE-2022-1342

A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*

History

24 Jun 2022, 01:24

Type Values Removed Values Added
References (MISC) https://devolutions.net/security/advisories/DEVO-2022-0003 - (MISC) https://devolutions.net/security/advisories/DEVO-2022-0003 - Vendor Advisory
CPE cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 4.6
CWE CWE-522

15 Jun 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-15 17:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-1342

Mitre link : CVE-2022-1342

CVE.ORG link : CVE-2022-1342


JSON object : View

Products Affected

devolutions

  • remote_desktop_manager
CWE
CWE-522

Insufficiently Protected Credentials

CWE-549

Missing Password Field Masking