PT-2024-37351 · Devolutions · Devolutions Remote Desktop Manager
Published
2024-06-17
·
Updated
2025-03-28
·
CVE-2024-6057
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Devolutions Remote Desktop Manager versions 2024.1.31.0 and earlier
Description:
The issue concerns improper authentication in the vault password feature, allowing an attacker with compromised access to an RDM instance to bypass the vault master password via the offline mode feature.
Recommendations:
For Devolutions Remote Desktop Manager versions 2024.1.31.0 and earlier, as a temporary workaround, consider disabling the offline mode feature until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devolutions Remote Desktop Manager