CVE-2022-3781
MEDIUMDevolutions Server < 2022.3.2 - Insufficiently Protected Credentials
Title source: ruleDescription
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.
Scores
CVSS v3
6.5
EPSS
0.0010
EPSS Percentile
27.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
CWE-311
Status
published
Affected Products (2)
devolutions/devolutions_server
< 2022.3.2
devolutions/remote_desktop_manager
< 2022.2.27
Timeline
Published
Nov 01, 2022
Tracked Since
Feb 18, 2026