First published: Thu Mar 23 2023(Updated: )
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Credit: security@devolutions.net
Affected Software | Affected Version | How to fix |
---|---|---|
Devolutions Remote Desktop Manager | <2023.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1202.
The title of the vulnerability is "Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager."
The vulnerability allows users with restricted rights to bypass entry permission via id collision when importing or synchronizing entries in the User vault.
The affected software is Devolutions Remote Desktop Manager version 2023.1.9 and prior versions.
The severity of the vulnerability is medium with a CVSS score of 6.5.
To fix the vulnerability, users should update to Devolutions Remote Desktop Manager version 2023.1.10 or later.