SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-3545

Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the…

MEDIUM 4.3EPSS 0.28%

Does this matter?

Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.

Description

Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
0.28% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-281
Affected
devolutions/devolutions server · devolutions/remote desktop manager
Source
security@devolutions.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.