CVE-2022-3781

MEDIUM

Devolutions Server < 2022.3.2 - Insufficiently Protected Credentials

Title source: rule
STIX 2.1

Description

Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522 CWE-311
Status published
Products (2)
devolutions/devolutions_server < 2022.3.2
devolutions/remote_desktop_manager < 2022.2.27
Published Nov 01, 2022
Tracked Since Feb 18, 2026