Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack.
Versions affected are :
Remote Desktop Manager macOS 2024.3.9.0 and earlier
Remote Desktop Manager Linux 2024.3.2.5 and earlier
Remote Desktop Manager Android 2024.3.3.7 and earlier
Remote Desktop Manager iOS 2024.3.3.0 and earlier
Remote Desktop Manager Powershell 2024.3.6.0 and earlier
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2025-0001/ |
![]() ![]() |
History
Fri, 28 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Devolutions
Devolutions remote Desktop Manager Devolutions remote Desktop Manager Powershell |
|
CPEs | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:android:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:linux:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:macos:*:* cpe:2.3:a:devolutions:remote_desktop_manager_powershell:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Devolutions
Devolutions remote Desktop Manager Devolutions remote Desktop Manager Powershell |
Mon, 10 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 10 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier |
Mon, 10 Feb 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier | |
Weaknesses | CWE-295 | |
References |
|

Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2025-02-12T15:17:11.387Z
Reserved: 2024-11-22T13:56:59.218Z
Link: CVE-2024-11621

Updated: 2025-02-10T15:37:58.735Z

Status : Analyzed
Published: 2025-02-10T14:15:29.490
Modified: 2025-03-28T16:20:47.230
Link: CVE-2024-11621

No data.