← Back

CVE-2024-3545

nvd nist
Published: Apr 9, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 0.9 / Impact: 3.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.

Affected (3)

2 products
Devolutions Server
Remote Desktop Manager
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 2024.1.9.0
Devolutions
Before 2024.1.21.0
Before 2024.1.21.0

References (2)

Source: security@devolutions.net
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.