5.4

CVE-2025-2499

Client side access control bypass in the permission component in 
Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. 

This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DevolutionsRemote Desktop Manager SwEditionfree SwPlatformwindows Version < 2024.3.31.0
DevolutionsRemote Desktop Manager SwEditionteam SwPlatformwindows Version < 2024.3.31.0
DevolutionsRemote Desktop Manager SwEditionfree SwPlatformwindows Version >= 2025.1.24.0 < 2025.1.26.0
DevolutionsRemote Desktop Manager SwEditionteam SwPlatformwindows Version >= 2025.1.24.0 < 2025.1.26.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.254
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://devolutions.net/security/advisories/DEVO-2025-0005/
Vendor Advisory