CVE-2022-26964: High severity remote desktop manager vulnerability
Published Dec 26, 2022
·Updated
Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.
Affected Software
1 affected component
Devolutions Remote Desktop Manager<2022.1
Event History
Dec 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Devolutions Remote Desktop Manager?
The vulnerability ID for this issue in Devolutions Remote Desktop Manager is CVE-2022-26964.
2
What is the severity rating of CVE-2022-26964?
The severity rating of CVE-2022-26964 is high, with a value of 7.5.
3
How does CVE-2022-26964 allow information disclosure?
CVE-2022-26964 allows information disclosure via a password brute-force attack.
4
What version of Devolutions Remote Desktop Manager is affected by CVE-2022-26964?
CVE-2022-26964 affects Devolutions Remote Desktop Manager before version 2022.1.
5
Is there a fix available for CVE-2022-26964?
Yes, a fix for CVE-2022-26964 is available in Devolutions Remote Desktop Manager version 2022.1 and later.