CVE-2023-1939
Last modified
CVE-2023-1939 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Devolutions | Remote Desktop Manager | <= 2022.3.2.0 |
| Devolutions | Remote Desktop Manager | <= 2022.3.33.0 |
References
- https://devolutions.net/security/advisories/DEVO-2023-0009Vendor Advisory
- https://devolutions.net/security/advisories/DEVO-2023-0009Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-1939?
How severe is CVE-2023-1939?
How do I fix CVE-2023-1939?
Are you affected by CVE-2023-1939?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
