First published: Tue Apr 25 2023(Updated: )
Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.
Credit: security@devolutions.net
Affected Software | Affected Version | How to fix |
---|---|---|
Devolutions Remote Desktop Manager | <=2023.1.22 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2282 is a vulnerability in Devolutions Remote Desktop Manager that allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.
CVE-2023-2282 affects Devolutions Remote Desktop Manager by allowing an authenticated user to bypass administrator-enforced Web Login restrictions.
CVE-2023-2282 affects Devolutions Remote Desktop Manager version 2023.1.22 and earlier.
The severity of CVE-2023-2282 is medium, with a CVSS score of 6.5.
To fix CVE-2023-2282, users should update to a version of Devolutions Remote Desktop Manager that is not affected by the vulnerability. Check the vendor's website for the latest updates and patches.