Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://devolutions.net/security/advisories/DEVO-2024-0006 |
![]() ![]() |
History
Fri, 28 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Devolutions
Devolutions devolutions Server Devolutions remote Desktop Manager |
|
CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:* cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:* |
|
Vendors & Products |
Devolutions
Devolutions devolutions Server Devolutions remote Desktop Manager |
Mon, 04 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-281 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2024-11-04T16:46:03.419Z
Reserved: 2024-04-09T18:43:05.078Z
Link: CVE-2024-3545

Updated: 2024-08-01T20:12:07.633Z

Status : Analyzed
Published: 2024-04-09T19:15:41.380
Modified: 2025-03-28T16:20:52.220
Link: CVE-2024-3545

No data.