CVE Vulnerabilities

CVE-2024-52940

Insertion of Sensitive Information into Log File

Published: Nov 18, 2024 | Modified: Nov 18, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victims AnyDesk ID.

Weakness

The product writes sensitive information to a log file.

Potential Mitigations

References