First published: Wed Jun 15 2022(Updated: )
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.
Credit: security@devolutions.net
Affected Software | Affected Version | How to fix |
---|---|---|
Devolutions Remote Desktop Manager | <=2022.1.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1342 is a vulnerability found in Devolutions Remote Desktop Manager that allows physically proximate attackers to observe sensitive data due to a lack of password masking.
CVE-2022-1342 can cause sensitive fields in Devolutions Remote Desktop Manager to sometimes stay revealed when closing and reopening a panel, potentially leading to the inadvertent disclosure of sensitive information.
CVE-2022-1342 has a severity level of medium, with a CVSS score of 4.6.
To fix CVE-2022-1342 in Devolutions Remote Desktop Manager, it is recommended to update to version 2022.1.24 or later, which addresses the vulnerability.
You can find more information about CVE-2022-1342 in Devolutions Remote Desktop Manager in the security advisory provided by Devolutions: [https://devolutions.net/security/advisories/DEVO-2022-0003]