Description
Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.
References
https://devolutions.net/security/advisories/DEVO-2023-0012
Vendor Advisory
https://devolutions.net/security/advisories/DEVO-2023-0012
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2023-04-25T19:15:11.100
2 years agoLast modified
2025-02-04T15:15:17.270
3 months ago