PT-2023-18713 · Devolutions · Devolutions Remote Desktop Manager
Publicado
2023-04-25
·
Atualizado
2023-05-04
·
CVE-2023-2282
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Remote Desktop Manager versions 2023.1.22 and earlier
Description
The issue is related to improper access control in the Web Login listener, allowing an authenticated user to bypass administrator-enforced Web Login restrictions. This can be achieved via an unexpected vector, potentially granting access to entries that should be restricted.
Recommendations
For Devolutions Remote Desktop Manager versions 2023.1.22 and earlier, update to a version that addresses the improper access control issue to prevent bypassing of Web Login restrictions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Devolutions Remote Desktop Manager