CVE Vulnerabilities

CVE-2022-1342

Missing Password Field Masking

Published: Jun 15, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.

Weakness

The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.

Affected Software

Name Vendor Start Version End Version
Remote_desktop_manager Devolutions * 2022.1.24 (including)

Potential Mitigations

References