Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program routines Config export/generation routines.
This issue affects RustDesk Server Pro: through 1.7.5.
Default — any deployment using "Encrypted Config" strings
PoC available. Trivially exploitable.
Treat config strings as public; restrict distribution to trusted channels only
Implement AES-256-GCM AEAD or equivalent authenticated encryption