8.8
CVE-2024-11621
- EPSS 0.23%
- Veröffentlicht 10.02.2025 14:15:29
- Zuletzt bearbeitet 28.03.2025 16:20:47
- Erkennungen
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devolutions ≫ Remote Desktop Manager SwPlatform linux Version < 2024.3.2.9
Devolutions ≫ Remote Desktop Manager SwPlatform iphone_os Version < 2024.3.4.0
Devolutions ≫ Remote Desktop Manager SwPlatform android Version < 2024.3.4.2
Devolutions ≫ Remote Desktop Manager SwPlatform macos Version < 2024.3.10.3
Devolutions ≫ Remote Desktop Manager Powershell Version < 2024.3.7
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.138 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://devolutions.net/security/advisories/DEVO-2025-0001/