CVE-2022-3781

MEDIUM

Devolutions Server < 2022.3.2 - Insufficiently Protected Credentials

Title source: rule

Description

Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 27.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522 CWE-311
Status published

Affected Products (2)

devolutions/devolutions_server < 2022.3.2
devolutions/remote_desktop_manager < 2022.2.27

Timeline

Published Nov 01, 2022
Tracked Since Feb 18, 2026