Executive brief
SmartIT Desktop Manager is a desktop management application used to remotely manage user systems. An unauthenticated attacker can extract SFTP credentials from the application source code and use them to browse and access files on a user's host without authorization, leading to unauthorized file system access and potential data exposure.
Technical details
This vulnerability is a Use of Hard-coded Credentials (CWE-798) in SmartIT Desktop Manager version 10 and earlier. The SFTP service account credentials for the SmartIT Agent application are embedded directly in the application source code in plaintext. An unauthenticated remote attacker can extract these credentials and use them to establish SFTP connections to user systems, bypassing authentication requirements and gaining unauthorized access to the file system. No authentication is required; the attacker simply needs access to the application source code. A patch is available in version 11 and later.
Affected products
- Lightstar SmartIT Desktop Manager 10 and earlier
Timeline
- 2026-09-04: disclosed