PT-2024-37351 · Devolutions · Devolutions Remote Desktop Manager

Published

2024-06-17

·

Updated

2025-03-28

·

CVE-2024-6057

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Devolutions Remote Desktop Manager versions 2024.1.31.0 and earlier
Description: The issue concerns improper authentication in the vault password feature, allowing an attacker with compromised access to an RDM instance to bypass the vault master password via the offline mode feature.
Recommendations: For Devolutions Remote Desktop Manager versions 2024.1.31.0 and earlier, as a temporary workaround, consider disabling the offline mode feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6057

Affected Products

Devolutions Remote Desktop Manager