PT-2023-17968 · Devolutions · Devolutions Server

Jico

·

Publicado

2023-04-21

·

Atualizado

2023-04-29

·

CVE-2023-2118

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2023.1.5.0 and below
Description The issue is related to insufficient access control in the support ticket feature, allowing an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.
Recommendations For Devolutions Server versions 2023.1.5.0 and below, consider restricting access to the support ticket feature until a fix is available. As a temporary workaround, limit the ability to send support tickets and download diagnostic files to authorized personnel only. Avoid using the vulnerable support ticket feature in Devolutions Server until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-2118

Produtos afetados

Devolutions Server