QID 379270
Date Published: 2024-01-29
QID 379270: Multi-Remote Next Generation Connection Manager (mRemoteNG) Password Dumper Vulnerability
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version less than v1.76.21 and less than 1.77.4-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet.
Affected Version :
mRemoteNG version prior to v1.76.21
QID Detection Logic (Authenticated):
This qid checks for file version of mRemoteNG.exe
It allows attackers to access contents of configuration files in plain text through a memory dump and thus compromise user credentials when no custom password encryption key has been set.
- CVE-2023-30367 -
github.com/S1lkys/CVE-2023-30367-mRemoteNG-password-dumper
CVEs related to QID 379270
| Advisory ID | Software | Component | Link |
|---|