CVE-2023-30367

Source
https://cve.org/CVERecord?id=CVE-2023-30367
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30367.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-30367
Published
2023-07-26T21:15:09.980Z
Modified
2026-04-10T04:57:20.108304Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet. This allows attackers to access contents of configuration files in plain text through a memory dump and thus compromise user credentials when no custom password encryption key has been set. This also bypasses the connection configuration file encryption setting by dumping already decrypted configurations from memory.

References

Affected packages

Git / github.com/mremoteng/mremoteng

Affected ranges

Type
GIT
Repo
https://github.com/mremoteng/mremoteng
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.76.20"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.77.2-nb"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.77.3-nb"
        }
    ]
}

Affected versions

1.*
1.50
1.60
1.62
1.63
1.64
1.65
1.66
1.67
1.67RC1
1.67RC2
1.67RC3
1.67RC4
1.67RC5
1.68
1.70Beta1
1.70Beta2
1.71Beta1
1.71Beta2
1.71Beta3
1.71Beta4
1.71Beta5
1.73Beta1
1.73Beta2
1.77.2
2022.*
2022.01.07-1.77.2-nb
2022.06.13-v1.77.3-nb
20220613-v1.*
20220613-v1.77.3-nb
v1.*
v1.75Alpha2
v1.75Alpha3
v1.75Aplha1
v1.75Beta1
v1.75Beta2
v1.75Beta3
v1.75RC1
v1.76.10
v1.76.12
v1.76.13
v1.76.14
v1.76.15
v1.76.16
v1.76.17
v1.76.18
v1.76.20
v1.76.5
v1.76.6
v1.76.7
v1.76.8
v1.76.9
v1.76Alpha1
v1.76Alpha2
v1.76Alpha3
v1.76Alpha4
v1.76Alpha5
v1.76Alpha6
v1.77.0
v1.77.1
v1.77.2
v1.77.2-nb
v1.77.3-nb
v1.77Alpha1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30367.json"