4.3
CVE-2023-1939
- EPSS 0.4%
- Veröffentlicht 11.04.2023 18:15:58
- Zuletzt bearbeitet 10.02.2025 19:15:36
- Erkennungen
No access control for the OTP key on OTP entries
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devolutions ≫ Remote Desktop Manager SwPlatform linux Version <= 2022.3.2.0
Devolutions ≫ Remote Desktop Manager SwPlatform windows Version <= 2022.3.33.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.32 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://devolutions.net/security/advisories/DEVO-2023-0009