CVE-2024-7421: Devolutions Remote Desktop Manager

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions

Affected products

  • Devolutions Remote Desktop Manager: before 2024.3.10 (fixed in 2024.3.10)

Published 2024-09-25. Last modified 2026-06-17.