CVE-2023-6588: Medium severity devolutions workspace vulnerability
Published Dec 7, 2023
·Updated
Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.
Affected Software
1 affected component
Devolutions Workspace<=2023.3.2.0
Event History
Dec 7, 2023
CVE Published
03:59 PM
Data Sourced
03:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-6588?
CVE-2023-6588 is considered a critical vulnerability due to its potential to expose credentials while offline.
2
How do I fix CVE-2023-6588?
To fix CVE-2023-6588, upgrade to Devolutions Workspace version 2023.3.2.1 or later.
3
Who is affected by CVE-2023-6588?
CVE-2023-6588 affects users of Devolutions Workspace versions up to and including 2023.3.2.0.
4
What is the impact of CVE-2023-6588?
The impact of CVE-2023-6588 allows unauthorized access to sensitive credentials in offline mode.
5
What products are impacted by CVE-2023-6588?
CVE-2023-6588 impacts the Devolutions Workspace product specifically.