Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2023-0022
Devolutions Password Manager is affected by a vulnerability.
Affected Products
Change Log
2023-12-07 - Initial publication
Offline mode permission not enforced
2.3 Low - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green
Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Password Manager 2023.3.2.0 and earlier. This allows an attacker with access to the Devolutions Password Manager application to access credentials when offline.
CVE(s)
CVE-2023-6588
Remediation and Workarounds
Upgrade to Devolutions Password Manager 2023.3.0 or higher.