4.3
CVE-2023-1939
- EPSS 0.2%
- Veröffentlicht 11.04.2023 18:15:58
- Zuletzt bearbeitet 10.02.2025 19:15:36
- Quelle security@devolutions.net
- CVE-Watchlists
- Unerledigt
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devolutions ≫ Remote Desktop Manager SwPlatformlinux Version <= 2022.3.2.0
Devolutions ≫ Remote Desktop Manager SwPlatformwindows Version <= 2022.3.33.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.421 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.