CVE-2023-5765

Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:42

Type Values Removed Values Added
References () https://devolutions.net/security/advisories/DEVO-2023-0019/ - Vendor Advisory () https://devolutions.net/security/advisories/DEVO-2023-0019/ - Vendor Advisory

09 Nov 2023, 01:26

Type Values Removed Values Added
First Time Microsoft
Devolutions
Microsoft windows
Devolutions remote Desktop Manager
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-Other
References (MISC) https://devolutions.net/security/advisories/DEVO-2023-0019/ - (MISC) https://devolutions.net/security/advisories/DEVO-2023-0019/ - Vendor Advisory

01 Nov 2023, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-01 18:15

Updated : 2024-11-21 08:42


NVD link : CVE-2023-5765

Mitre link : CVE-2023-5765

CVE.ORG link : CVE-2023-5765


JSON object : View

Products Affected

devolutions

  • remote_desktop_manager

microsoft

  • windows