Show filters
82 Total Results
Displaying 11-20 of 82
Sort by:
Attacker Value
Unknown
CVE-2024-11670
Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
0
Attacker Value
Unknown
CVE-2024-10971
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
0
Attacker Value
Unknown
CVE-2024-7421
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
0
Attacker Value
Unknown
CVE-2024-6512
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
0
Attacker Value
Unknown
CVE-2024-6492
Disclosure Date: July 16, 2024 (last updated July 17, 2024)
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.
0
Attacker Value
Unknown
CVE-2024-6354
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
0
Attacker Value
Unknown
CVE-2024-4846
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.
0
Attacker Value
Unknown
CVE-2024-6057
Disclosure Date: June 17, 2024 (last updated June 18, 2024)
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.
0
Attacker Value
Unknown
CVE-2024-6055
Disclosure Date: June 17, 2024 (last updated June 18, 2024)
Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.
0
Attacker Value
Unknown
CVE-2024-5072
Disclosure Date: May 17, 2024 (last updated May 18, 2024)
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.
0