CVE-2023-0463: High severity remote desktop manager vulnerability
The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-0463.
What is the title of the vulnerability?
The title of the vulnerability is 'The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.'
Which software is affected by this vulnerability?
Devolutions Remote Desktop Manager 2022.3.29 and 2022.3.30 are affected by this vulnerability.
What is the severity of the vulnerability?
The severity of the vulnerability is low (CVSS score 3.3).
How can I fix this vulnerability?
There is no specific fix mentioned in the reference link provided, so it is recommended to update to the latest version of Devolutions Remote Desktop Manager to mitigate the vulnerability.