First published: Tue Dec 12 2023(Updated: )
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
Credit: security@devolutions.net
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Remote Desktop Manager | <2023.3.5.0 | |
iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6593 is considered a critical vulnerability due to its potential for client-side permission bypass.
To mitigate CVE-2023-6593, update Devolutions Remote Desktop Manager to version 2023.3.5.0 or later.
CVE-2023-6593 may allow an attacker with access to the application to execute SQL commands without proper restrictions.
CVE-2023-6593 affects versions 2023.3.4.0 and earlier of Devolutions Remote Desktop Manager.
Users of Devolutions Remote Desktop Manager on iOS versions 2023.3.4.0 and earlier are susceptible to CVE-2023-6593.