PT-2025-6046 · Devolutions · Devolutions Remote Desktop Manager

Published

2025-02-10

·

Updated

2025-02-14

·

CVE-2025-1193

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions 2024.3.19 and earlier
Description The issue is related to improper host validation in the certificate validation component, allowing an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.
Recommendations For Devolutions Remote Desktop Manager versions 2024.3.19 and earlier, update to a version later than 2024.3.19 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-1193

Affected Products

Devolutions Remote Desktop Manager