PT-2024-17178 · Devolutions · Devolutions Remote Desktop Manager

Published

2024-11-25

·

Updated

2024-11-25

·

CVE-2024-11670

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions 2024.2.21 and earlier
Description The issue is related to incorrect authorization in the permission validation component, allowing a malicious authenticated user to bypass the "View Password" permission via specific actions. This can lead to unauthorized access.
Recommendations For Devolutions Remote Desktop Manager versions 2024.2.21 and earlier, update to the latest patched version immediately to resolve the issue. As a temporary workaround, consider restricting access to sensitive password information until the update is applied.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-11670

Affected Products

Devolutions Remote Desktop Manager