Show filters
82 Total Results
Displaying 11-20 of 82
Sort by:
Attacker Value
Unknown

CVE-2024-11670

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
0
Attacker Value
Unknown

CVE-2024-10971

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
0
Attacker Value
Unknown

CVE-2024-7421

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
Attacker Value
Unknown

CVE-2024-6512

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
Attacker Value
Unknown

CVE-2024-6492

Disclosure Date: July 16, 2024 (last updated July 17, 2024)
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.
0
Attacker Value
Unknown

CVE-2024-6354

Disclosure Date: June 26, 2024 (last updated June 27, 2024)
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
0
Attacker Value
Unknown

CVE-2024-4846

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.
0
Attacker Value
Unknown

CVE-2024-6057

Disclosure Date: June 17, 2024 (last updated June 18, 2024)
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.
0
Attacker Value
Unknown

CVE-2024-6055

Disclosure Date: June 17, 2024 (last updated June 18, 2024)
Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.
0
Attacker Value
Unknown

CVE-2024-5072

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.
0