漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
Vulnerability Description
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks.
The client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book.
This vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password).
This issue affects RustDesk Client: through 1.4.8.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
RustDesk Server PRO 安全漏洞
Vulnerability Description
RustDesk Server PRO是RustDesk个人开发者的一个远程桌面服务器管理脚本集。 RustDesk Server PRO 1.7.5及之前版本存在安全漏洞,该漏洞源于敏感信息明文传输,可能导致嗅探攻击。
CVSS Information
N/A
Vulnerability Type
N/A