CVE-2023-30367

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-30367
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-30367.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-30367
Published
2023-07-26T21:15:09.980Z
Modified
2025-11-15T06:28:44.796814Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet. This allows attackers to access contents of configuration files in plain text through a memory dump and thus compromise user credentials when no custom password encryption key has been set. This also bypasses the connection configuration file encryption setting by dumping already decrypted configurations from memory.

References

Affected packages

Git / github.com/mremoteng/mremoteng

Affected ranges

Type
GIT
Repo
https://github.com/mremoteng/mremoteng
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected

Affected versions

1.*

1.50
1.60
1.61
1.62
1.63
1.64
1.65
1.66
1.67
1.67RC1
1.67RC2
1.67RC3
1.67RC4
1.67RC5
1.68
1.69
1.69RC1
1.70
1.70Beta1
1.70Beta2
1.70RC1
1.70RC2
1.70RC3
1.71
1.71Beta1
1.71Beta2
1.71Beta3
1.71Beta4
1.71Beta5
1.71RC2
1.71RC3
1.72
1.73Beta1
1.73Beta2
1.74Alpha1
1.74RC1
1.74RC2

v1.*

v1.74
v1.74RC3
v1.75
v1.75.7009
v1.75.7010
v1.75.7011
v1.75.7011.r1
v1.75.7012
v1.75Alpha2
v1.75Alpha3
v1.75Aplha1
v1.75Beta1
v1.75Beta2
v1.75Beta3
v1.75Hotfix1
v1.75Hotfix2
v1.75Hotfix3
v1.75Hotfix4
v1.75Hotfix5
v1.75Hotfix6
v1.75Hotfix7
v1.75Hotfix8
v1.75Hotifx7
v1.75RC1
v1.76.10
v1.76.12
v1.76.13
v1.76.14
v1.76.15
v1.76.16
v1.76.17
v1.76.18
v1.76.20
v1.76.5
v1.76.6
v1.76.7
v1.76.8
v1.76.9
v1.76Alpha1
v1.76Alpha2
v1.76Alpha3
v1.76Alpha4
v1.76Alpha5
v1.76Alpha6

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-30367.json"