CVE-2022-3781
MEDIUMDevolutions Server < 2022.3.2 - Insufficiently Protected Credentials
Title source: ruleDescription
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.
Scores
CVSS v3
6.5
EPSS
0.0008
EPSS Percentile
24.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-522
CWE-311
Status
published
Products (2)
devolutions/devolutions_server
< 2022.3.2
devolutions/remote_desktop_manager
< 2022.2.27
Published
Nov 01, 2022
Tracked Since
Feb 18, 2026