Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2023-0008
Devolutions Server and Remote Desktop Manager are affected by multiple security vulnerabilities.
Affected Products
Change Log
Initial Publication - 2023-03-23
High (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N 7.3)
Permission bypass when importing or synchronizing entries (CVE-2023-1202)
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Affected Products
CVE(s)
CVE-2023-1202
Remediation and Workarounds
Update to Remote Desktop Manager 2023.1.10 or higher
High (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N 7.3)
Permission bypass when importing or synchronizing entries (CVE-2023-1603)
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Affected Products
CVE(s)
CVE-2023-1603
Remediation and Workarounds
Update to Devolutions Server 2023.1.3.0 or higher




