Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier
History

Fri, 28 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
Devolutions remote Desktop Manager Powershell
CPEs cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:android:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:linux:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:macos:*:*
cpe:2.3:a:devolutions:remote_desktop_manager_powershell:*:*:*:*:*:*:*:*
Vendors & Products Devolutions
Devolutions remote Desktop Manager
Devolutions remote Desktop Manager Powershell

Mon, 10 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Description Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier

Mon, 10 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
Description Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier
Weaknesses CWE-295
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2025-02-12T15:17:11.387Z

Reserved: 2024-11-22T13:56:59.218Z

Link: CVE-2024-11621

cve-icon Vulnrichment

Updated: 2025-02-10T15:37:58.735Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-10T14:15:29.490

Modified: 2025-03-28T16:20:47.230

Link: CVE-2024-11621

cve-icon Redhat

No data.