Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
History

Fri, 28 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:free:windows:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:team:windows:*:*

Thu, 13 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
CPEs cpe:2.3:a:devolutions:remote_desktop_manager:-:*:*:*:*:*:*:*
Vendors & Products Devolutions
Devolutions remote Desktop Manager
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2025-03-13T18:28:31.840Z

Reserved: 2024-06-26T16:15:40.371Z

Link: CVE-2024-6354

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.392Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-26T17:15:27.497

Modified: 2025-03-28T16:19:33.260

Link: CVE-2024-6354

cve-icon Redhat

No data.