Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2022-0002

A vulnerability can reduce the strength of some passwords when exporting data in Remote Desktop Manager.

Affected Products

Remote Desktop Manager
2021.2 and earlier

Change Log

Initial Publication - 2022-03-09

High - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weak password derivation on vault export

When exporting data out of Remote Desktop Manager, a password can be used to encrypt the file. For passwords that were also valid Base64, Remote Desktop Manager erroneously decoded them prior to password derivation which reduces the effective length of the password.

Affected Products

CVE(s)

CVE-2022-26964

Remediation and Workarounds

Update to Remote Desktop Manager 2022.1 or higher.

Devolutions Logo

Helping organizations control the IT chaos by providing highly-secure password, remote connection and privileged access management solutions.

DEVOLUTIONS

Legal & privacy | infos@devolutions.net

All rights reserved © 2025 Devolutions