PT-2023-17388 · Devolutions · Devolutions Remote Desktop Manager

Publicado

2023-04-11

·

Atualizado

2023-04-21

·

CVE-2023-1980

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions 2022.3.35 and earlier
Description The issue allows a two-factor authentication bypass on login, enabling users to cancel the two-factor authentication via the application user interface and open entries.
Recommendations For Devolutions Remote Desktop Manager versions 2022.3.35 and earlier, consider disabling the login feature that allows cancellation of two-factor authentication until a patch is available. As a temporary workaround, restrict access to sensitive entries that could be opened by exploiting this issue. Avoid using the affected login interface in Devolutions Remote Desktop Manager until the issue is resolved.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1980

Produtos afetados

Devolutions Remote Desktop Manager