CVE-2025-1636

MEDIUM

Devolutions Remote Desktop Manager < 2024.3.31.0 - Sensitive Information Exposure via Password History

Title source: llm
STIX 2.1

Description

Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0158
EPSS Percentile 72.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
devolutions/remote_desktop_manager < 2024.3.31.0 (2 CPE variants)
Published Mar 13, 2025
Tracked Since Feb 18, 2026