PT-2025-12980 · Devolutions · Devolutions Remote Desktop Manager

CVE-2025-2528

·

Publicado

2025-03-26

·

Atualizado

2025-07-02

CVSS v3.1

3.6

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions 2024.3.29 and earlier, Devolutions Remote Desktop Manager versions 2025.1.24 through 2025.1.25
Description The issue is related to improper authorization in the application password policy, allowing an authenticated user to use a configuration different from the one mandated by system administrators.
Recommendations For Devolutions Remote Desktop Manager versions 2024.3.29 and earlier, update to a version later than 2024.3.29. For Devolutions Remote Desktop Manager versions 2025.1.24 through 2025.1.25, update to a version later than 2025.1.25.

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-2528

Produtos afetados

Devolutions Remote Desktop Manager