CVE-2024-6057

CRITICAL

Devolutions Remote Desktop Manager < 2024.1.32.0 - Improper Authentication via Offline Mode Feature

Title source: llm
STIX 2.1

Description

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
devolutions/remote_desktop_manager < 2024.1.32.0 (2 CPE variants)
Published Jun 17, 2024
Tracked Since Feb 18, 2026