CVE-2023-1202
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Permission bypass when importing or synchronizing entries in User vault
in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Affected (1)
Products: Devolutions: Remote Desktop Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2023.1.10 |
References (2)
Source: security@devolutions.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.