CVE-2023-1980
https://notcve.org/view.php?id=CVE-2023-1980
Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries. • https://devolutions.net/security/advisories/DEVO-2023-0009 •
CVE-2023-1202
https://notcve.org/view.php?id=CVE-2023-1202
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision. • https://devolutions.net/security/advisories/DEVO-2023-0008 • CWE-863: Incorrect Authorization •
CVE-2023-1574
https://notcve.org/view.php?id=CVE-2023-1574
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text. • https://devolutions.net/security/advisories/DEVO-2023-0006 • CWE-522: Insufficiently Protected Credentials •
CVE-2023-0463
https://notcve.org/view.php?id=CVE-2023-0463
The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk. La configuración de forzar el aviso MFA sin conexión no se respeta al cambiar al modo sin conexión en Devolutions Remote Desktop Manager 2022.3.29 a 2022.3.30 permite al usuario guardar datos confidenciales en el disco. • https://devolutions.net/security/advisories/DEVO-2023-0001 •