Sicherheit & Regelkonformität

Wir halten die höchsten Standards ein, um Ihre Daten zu schützen und Vertrauen zu gewährleisten.

DEVO-2023-0008

Devolutions Server and Remote Desktop Manager are affected by multiple security vulnerabilities.

Betroffene Produkte

Remote Desktop Manager
2023.1.9 and below
Devolutions Server
2022.3.13 and below

Änderungsprotokoll

Initial Publication - 2023-03-23

High (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N 7.3)

Permission bypass when importing or synchronizing entries (CVE-2023-1202)

Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.

Betroffene Produkte

CVE(s)

CVE-2023-1202

Behebungen und Workarounds

Update to Remote Desktop Manager 2023.1.10 or higher

High (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N 7.3)

Permission bypass when importing or synchronizing entries (CVE-2023-1603)

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.

Betroffene Produkte

CVE(s)

CVE-2023-1603

Behebungen und Workarounds

Update to Devolutions Server 2023.1.3.0 or higher