CVE-2024-6354: High severity Devolutions Remote Desktop Manager vulnerability
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6354?
CVE-2024-6354 has a medium severity level due to the improper access control allowing unauthorized actions in Devolutions Remote Desktop Manager.
How do I fix CVE-2024-6354?
To fix CVE-2024-6354, upgrade Devolutions Remote Desktop Manager to version 2024.2.12 or later.
Who is affected by CVE-2024-6354?
CVE-2024-6354 affects all authenticated users of Devolutions Remote Desktop Manager versions 2024.2.11 and earlier.
What is the impact of CVE-2024-6354?
The impact of CVE-2024-6354 is that it allows an authenticated user to bypass execute permissions, potentially leading to unauthorized access.
Is there a workaround for CVE-2024-6354?
Currently, there is no documented workaround for CVE-2024-6354; upgrading to the latest version is the recommended solution.